What You Need To Know - ZyXEL Communications NXC5200 User Manual

Hide thumbs Also See for NXC5200:
Table of Contents

Advertisement

Chapter 18 Firewall

18.1.2 What You Need to Know

The following terms and concepts may help as you read this chapter.
Stateful Inspection
The NXC has a stateful inspection firewall. The NXC restricts access by screening
data packets against defined access rules. It also inspects sessions. For example,
traffic from one zone is not allowed unless it is initiated by a computer in another
zone first.
Zones
A zone is a group of interfaces. Group the NXC's interfaces into different zones
based on your needs. You can configure firewall rules for data passing between
zones or even between interfaces in a zone.
Default Firewall Behavior
Firewall rules are grouped based on the direction of travel of packets to which they
apply. Here is the default firewall behavior for traffic going through the NXC in
various directions.
Table 88 Default Firewall Behavior
FROM ZONE TO ZONE
From WAN to NXC
From WAN to any (other
than the NXC)
From DMZ to NXC
From DMZ to any (other
than the NXC)
From ANY to ANY
To-NXC Rules
Rules with NXC as the To Zone apply to traffic going to the NXC itself. By default:
• The firewall allows only LAN, WAN computers to access or manage the NXC.
• The NXC drops most packets from the WAN zone to the NXC itself, except for
VRRP traffic for Device HA, and generates a log.
250
BEHAVIOR
Traffic from the WAN to the NXC itself is allowed for certain
default services described in
other WAN to NXC traffic is dropped.
Traffic from the WAN to any of the networks behind the NXC is
dropped.
Traffic from the DMZ to the NXC itself is allowed for certain
default services described in
other DMZ to NXC traffic is dropped.
Traffic from the DMZ to any of the networks behind the NXC is
dropped.
Traffic that does not match any firewall rule is allowed. So for
example, LAN to WAN, LAN to DMZ, and LAN to WLAN traffic is
allowed. This also includes traffic to or from interfaces that are
not assigned to a zone (extra-zone traffic).
To-NXC Rules on page
250. All
To-NXC Rules on page
250. All
NXC5200 User's Guide

Advertisement

Table of Contents
loading

This manual is also suitable for:

Nxc5200 - v2.20

Table of Contents