Configuration Scenarios
Step-by-step guides for common TOORCE Firewall deployments. Each scenario includes a network design diagram and links to the relevant configuration pages.
Available scenarios
| Scenario | Description |
|---|---|
| NAT Gateway | LAN clients reach the internet through the firewall using Source NAT (outgoing interface address) |
| X-Pool Overlapping NAT | Two sites share the same subnet — use X-Pool SNAT for LAN-initiated traffic and DNAT for remote-initiated traffic |
| SSO Policy (Active Directory) | Connect AD, install Logon Forwarder on the DC, enable SSO listener, and assign SSO groups to inline rules |
| FQDN Allow / Block Policy | Allow or deny traffic by FQDN — firewall re-resolves IPs every 60 seconds (no wildcards or regex) |
| Remote SIEM & SMTP Notifications | Forward logs to a remote SIEM/syslog server and send email alerts to admins via SMTP |
| Administrator RBAC Profiles | Read-only, view-only, and read/write admin roles using Access profiles |
| SDWAN Multi-WAN | Load balance, weighted, and failover modes with packet-flow diagrams and full form reference |
| L2TP over IPsec VPN | L2TP server with IPsec PSK — native Windows and macOS VPN client setup |
| Web Filter Categories | Block URL categories (streaming), exact and regex overrides, assign Web Filter to inline rules |
| Time & GeoIP LAN Access | Sun–Thu 08:00–17:00 internet access with destination country allow-list; Source GeoIP for DNAT |
| IPSec Overlapping Subnets | Same local/remote subnet — Install Policy, Phase 2 selectors, X-Pool SNAT, VPN interface on rule |
| IPSec Local ↔ Remote Rules | Two inline rules with example IPs — LAN→VPN (outbound) and WAN→LAN (inbound) with address restrictions |
| SSL VPN Multi-Pool | Multiple client pools, VIP/dnat listen rule from WAN, SSL interface → LAN rules with full separation |
| ZTA Access Policy | Enforce ZTA Access, allowed assets, MFA/device binding, TOORCE RDP/Browser/SSH, temporary credentials, and file transfer control |
How to use these guides
- Read the network design diagram to understand interfaces, routing, and traffic flow.
- Follow the numbered steps in order — interfaces and routes must exist before inline rules.
- Click Install Policy after rule changes to apply them to the running firewall.
- Verify connectivity from a LAN client and check Firewall Security Logs.
Related documentation
- Object Reference Guide — recommended configuration order
- Network Interfaces
- Static Routes
- Inline Rules