Installation Guide
Purpose of This Document
This guide explains how to deploy Firegate™ correctly in an inline configuration between your modem and router.
Firegate is designed to operate transparently while enforcing security policies in real time.
For architectural details, see the Security Architecture section.
1. Deployment Model
Firegate must be installed inline using the following structure:
Modem → Firegate → Router → Internal Network
Firegate does not replace your router.
Your router continues to provide Wi-Fi, DHCP, and internal network services.
2. Interface Overview
Firegate uses three network interfaces:
- Internet IN – connected to the modem
- Internet OUT – connected to the router WAN/Internet port
- Update / Management Interface – dedicated to secure update connectivity
The Internet IN and Internet OUT interfaces are used exclusively for inline traffic inspection.
They do not hold IP addresses and are not directly accessible from the network.
3. Physical Installation Steps
- Power off your modem and router.
- Connect the modem Ethernet output to Internet IN on Firegate.
- Connect Internet OUT on Firegate to the router’s WAN/Internet port.
- (If required) connect the Update/Management interface as instructed.
- Power on the modem and wait until fully synchronised.
- Power on Firegate and wait approximately 1–2 minutes.
- Power on the router.
Allow up to 2 minutes for the network to stabilise.
4. How Traffic Flows
When installed correctly:
- Traffic enters Firegate from the modem.
- Packets are inspected in real time.
- Malicious or policy-violating traffic is blocked.
- Allowed traffic is forwarded to the router.
Firegate operates inline and does not act as the network gateway.
No changes to router gateway settings are required.
5. Update & Management Connectivity
Firegate uses a dedicated management interface to establish secure outbound connectivity to authorised QuantumSabre update infrastructure.
The system:
- Does not require inbound port forwarding
- Does not expose administrative services to the internet
- Does not require a public static IP
All update communication is outbound and encrypted.
6. Verifying Installation
After installation:
- Connect a device to your Wi-Fi network.
- Confirm that websites load normally.
- If a test mechanism is provided, run the test to confirm enforcement is active.
If internet connectivity does not restore:
- Restart the modem
- Restart the router
- Ensure all cables are securely connected
See Troubleshooting for additional diagnostics.
7. Important Notes
- Firegate must be placed between modem and router to function correctly.
- Installing Firegate behind the router (LAN side only) will not provide full network protection.
- Firegate does not replace Wi-Fi functionality.
- The inline inspection interfaces are intentionally non-addressable to reduce attack surface.
8. Emergency Bypass Procedure
If immediate connectivity is required:
- Disconnect Firegate.
- Connect modem directly to router WAN port.
- Restart the router.
Reconnect Firegate after resolving the issue.
9. Summary
Firegate provides inline network-level protection without requiring router reconfiguration or gateway replacement.
The device inspects traffic between modem and router while maintaining isolation between inspection interfaces and management connectivity.
