Chapter 5 Configuration Basics
5.2 Zones, Interfaces, and Physical Ports
Zones (groups of interfaces and VPN tunnels) simplify security settings. Here is an overview
of zones, interfaces, and physical ports in the ZyWALL.
Figure 43 Zones, Interfaces, and Physical Ethernet Ports
Zones
Interfaces
Physical Ports
Table 22 Zones, Interfaces, and Physical Ethernet Ports
Zones
(WAN, LAN, DMZ)
Interfaces
(Ethernet, VLAN,...)
Physical Ethernet
Ports
(P1, P2,...)
5.2.1 Interface Types
There are many types of interfaces in the ZyWALL. In addition to being used in various
features, interfaces also describe the network that is directly connected to the ZyWALL.
• Ethernet interfaces are the foundation for defining other interfaces and network policies.
You also configure RIP and OSPF in these interfaces.
• Port groups create a hardware connection between physical ports at the layer-2 (data link,
MAC address) level.
• PPPoE/PPTP interfaces support Point-to-Point Protocols (PPP). ISP accounts are
required for PPPoE/PPTP interfaces.
• VLAN interfaces recognize tagged frames. The ZyWALL automatically adds or removes
the tags as needed. Each VLAN can only be associated with one Ethernet interface.
• Bridge interfaces create a software connection between Ethernet or VLAN interfaces at
the layer-2 (data link, MAC address) level. Then, you can configure the IP address and
subnet mask of the bridge. It is also possible to configure zone-level security between the
member interfaces in the bridge.
108
LAN
WAN
ge1
ge2 ge3
P1
P2
A zone is a group of interfaces and VPN tunnels. Use zones to apply security
settings such as firewall, IDP, remote management, anti-virus, and application
patrol.
Interfaces are logical entities that (layer-3) packets pass through. Use
interfaces in configuring VPN, zones, trunks, device HA, DDNS, policy routes,
static routes, HTTP redirect, and virtual server.
Port groups combine physical ports into interfaces.
The physical port is where you connect a cable. In configuration, you use
physical ports when configuring port groups. You use interfaces and zones in
configuring other features.
DMZ
ge4
ge5
P3
P4
P5
ZyWALL 1050 User's Guide