ZyXEL Communications NXC5200 User Manual page 258

Hide thumbs Also See for NXC5200:
Table of Contents

Advertisement

Chapter 18 Firewall
• The NXC applies NAT (Destination NAT) settings before applying the firewall
rules. So for example, if you configure a NAT entry that sends WAN traffic to a
LAN IP address, when you configure a corresponding firewall rule to allow the
traffic, you need to set the LAN IP address as the destination.
• The ordering of your rules is very important as rules are applied in sequence.
Figure 113 Configuration > Firewall
The following table describes the labels in this screen.
Table 92 Configuration > Firewall
LABEL
General
Settings
Enable
Firewall
Allow
Asymmetrical
Route
258
DESCRIPTION
Select this check box to activate the firewall. The NXC performs access
control when the firewall is activated.
If an alternate gateway on the LAN has an IP address in the same subnet
as the NXC's LAN IP address, return traffic may not go through the NXC.
This is called an asymmetrical or "triangle" route. This causes the NXC to
reset the connection, as the connection has not been acknowledged.
Select this check box to have the NXC permit the use of asymmetrical
route topology on the network (not reset the connection).
Note: Allowing asymmetrical routes may let traffic from the WAN go
directly to the LAN without passing through the NXC. A better
solution is to use virtual interfaces to put the NXC and the
backup gateway on separate subnets.
NXC5200 User's Guide

Advertisement

Table of Contents
loading

This manual is also suitable for:

Nxc5200 - v2.20

Table of Contents