Table 84 Default Firewall Rules - ZyXEL Communications Unified Security Gateway ZyWALL 1000 User Manual

Unified security gateway
Hide thumbs Also See for Unified Security Gateway ZyWALL 1000:
Table of Contents

Advertisement

The following table explains the default firewall rules for traffic going through the ZyWALL.
See
Section 19.2.1.2 on page 279
ZyWALL itself.

Table 84 Default Firewall Rules

FROM ZONE TO ZONE
From LAN to LAN
From LAN to WAN
From LAN to DMZ
From WAN to LAN
From WAN to WAN
From WAN to DMZ
From WAN to ZyWALL
From DMZ to LAN
From DMZ to WAN
From DMZ to DMZ
If you enable intra-zone traffic blocking (see the chapter about zones), the
firewall automatically creates (implicit) rules to deny packet passage between
the interfaces in the specified zone.
You also need to configure virtual servers (NAT port forwarding) to allow
computers on the WAN to access devices on the LAN. See
page 255
for more information.
19.2.1.1 Global Firewall Rules
If an interface or VPN tunnel is not included in a zone, only the global firewall rules (with
from any to any direction) apply to traffic going to and from that interface.
19.2.1.2 To-ZyWALL Rules
Rules with ZyWALL as the To Zone apply to traffic going to the ZyWALL itself. By default,
the firewall allows any computer from the LAN zone to access or manage the ZyWALL. By
default, the ZyWALL drops most packets from the WAN or DMZ zone to the ZyWALL itself,
except for VRRP traffic for Device HA and ESP/AH/IKE/NATT/HTTPS services for VPN
tunnels, and generates a log.
When you configure a to-ZyWALL rule for packets destined for the ZyWALL itself, make
sure it does not conflict with your service control rule. See
information about service control (remote management).
ZyWALL USG 1000 User's Guide
for details on the firewall rules for traffic going to the
STATEFUL PACKET INSPECTION
Traffic between interfaces in the LAN is allowed.
Traffic from the LAN to the WAN is allowed.
Traffic from the LAN to the DMZ is allowed.
Traffic from the WAN to the LAN is dropped.
Traffic between interfaces in the WAN is dropped.
Traffic from the WAN to the DMZ is allowed.
Traffic from the WAN to the ZyWALL itself is dropped except for
the traffic types described in
Traffic from the DMZ to the LAN is dropped.
Traffic from the DMZ to the WAN is dropped.
Traffic between interfaces in the DMZ is dropped.
Chapter 19 Firewall
Section 19.2.1.2 on page
279.
Chapter 16 on
Chapter 43 on page 575
for more
279

Advertisement

Table of Contents
loading

This manual is also suitable for:

Zywall usg 1000

Table of Contents