Firewall And Vpn Traffic; Firewall Rule Example Applications - ZyXEL Communications Unified Security Gateway ZyWALL 300 User Manual

Unified security gateway
Hide thumbs Also See for Unified Security Gateway ZyWALL 300:
Table of Contents

Advertisement

Chapter 19 Firewall
19.2.1.2 To-ZyWALL Rules
Rules with ZyWALL as the To Zone apply to traffic going to the ZyWALL itself. By default,
the firewall allows any computer from the LAN zone to access or manage the ZyWALL. By
default, the ZyWALL drops most packets from the WAN or DMZ zone to the ZyWALL itself,
except for VRRP traffic for Device HA and ESP/AH/IKE/NATT/HTTPS services for VPN
tunnels, and generates a log.
When you configure a to-ZyWALL rule for packets destined for the ZyWALL itself, make
sure it does not conflict with your service control rule. See
information about service control (remote management).
The ZyWALL checks the firewall rules before the service control rules for traffic
destined for the ZyWALL.
You can configure a to-ZyWALL firewall rule (with From Any To ZyWALL
direction) for traffic from an interface which is not in a zone.

19.2.2 Firewall and VPN Traffic

After you create a VPN tunnel and apply it to a zone, you can set the firewall rules applied to
VPN traffic. If you add a VPN tunnel to an existing zone (the LAN zone for example), you can
configure a new LAN to LAN firewall rule or use intra-zone traffic blocking to allow or block
VPN traffic transmitting between the VPN tunnel and other interfaces in the LAN zone. If you
add the VPN tunnel to a new zone (the VPN zone for example), you can configure rules for
VPN traffic between the VPN zone and other zones or From VPN To-ZyWALL rules for
VPN traffic destined for the ZyWALL.

19.3 Firewall Rule Example Applications

Suppose that your company decides to block all of the LAN users from using IRC (Internet
Relay Chat) through the Internet. To do this, you would configure a LAN to WAN firewall
rule that blocks IRC traffic from any source IP address from going to any destination address.
You do not need to specify a schedule since you need the firewall rule to always be in effect.
The following figure shows the results of this rule.
280
Chapter 44 on page 587
for more
ZyWALL USG 300 User's Guide

Advertisement

Table of Contents
loading

Table of Contents