Configuration Scenarios

Step-by-step guides for common TOORCE Firewall deployments. Each scenario includes a network design diagram and links to the relevant configuration pages.

Available scenarios

Scenario Description
NAT Gateway LAN clients reach the internet through the firewall using Source NAT (outgoing interface address)
X-Pool Overlapping NAT Two sites share the same subnet — use X-Pool SNAT for LAN-initiated traffic and DNAT for remote-initiated traffic
SSO Policy (Active Directory) Connect AD, install Logon Forwarder on the DC, enable SSO listener, and assign SSO groups to inline rules
FQDN Allow / Block Policy Allow or deny traffic by FQDN — firewall re-resolves IPs every 60 seconds (no wildcards or regex)
Remote SIEM & SMTP Notifications Forward logs to a remote SIEM/syslog server and send email alerts to admins via SMTP
Administrator RBAC Profiles Read-only, view-only, and read/write admin roles using Access profiles
SDWAN Multi-WAN Load balance, weighted, and failover modes with packet-flow diagrams and full form reference
L2TP over IPsec VPN L2TP server with IPsec PSK — native Windows and macOS VPN client setup
Web Filter Categories Block URL categories (streaming), exact and regex overrides, assign Web Filter to inline rules
Time & GeoIP LAN Access Sun–Thu 08:00–17:00 internet access with destination country allow-list; Source GeoIP for DNAT
IPSec Overlapping Subnets Same local/remote subnet — Install Policy, Phase 2 selectors, X-Pool SNAT, VPN interface on rule
IPSec Local ↔ Remote Rules Two inline rules with example IPs — LAN→VPN (outbound) and WAN→LAN (inbound) with address restrictions
SSL VPN Multi-Pool Multiple client pools, VIP/dnat listen rule from WAN, SSL interface → LAN rules with full separation
ZTA Access Policy Enforce ZTA Access, allowed assets, MFA/device binding, TOORCE RDP/Browser/SSH, temporary credentials, and file transfer control

How to use these guides

  1. Read the network design diagram to understand interfaces, routing, and traffic flow.
  2. Follow the numbered steps in order — interfaces and routes must exist before inline rules.
  3. Click Install Policy after rule changes to apply them to the running firewall.
  4. Verify connectivity from a LAN client and check Firewall Security Logs.

Related documentation