What You Need To Know - ZyXEL Communications NXC5200 User Manual

Hide thumbs Also See for NXC5200:
Table of Contents

Advertisement

Chapter 19 Application Patrol

19.1.2 What You Need to Know

The following terms and concepts may help as you read this chapter.
If you want to use a service, make sure both the firewall and application patrol
allow the service's packets to go through the NXC.
Note: The NXC checks firewall rules before it checks application patrol rules for traffic
going through the NXC.
Application patrol examines every TCP and UDP connection passing through the
NXC and identifies what application is using the connection. Then, you can specify,
by application, whether or not the NXC continues to route the connection.
Configurable Application Policies
The NXC has policies for individual applications. For each policy, you can specify
the default action the NXC takes once it identifies one of the service's connections.
You can also specify custom policies that have the NXC forward, drop, or reject a
service's connections based on criteria that you specify (like the source zone,
destination zone, original destination port of the connection, schedule, user,
source, and destination information). Your custom policies take priority over the
policy's default settings.
Classification of Applications
There are two ways the NXC can identify the application. The first is called auto.
The NXC looks at the IP payload (OSI level-7 inspection) and attempts to match it
with known patterns for specific applications. Usually, this occurs at the beginning
of a connection, when the payload is more consistent across connections, and the
NXC examines several packets to make sure the match is correct.
Note: The NXC allows the first eight packets to go through the firewall, regardless of
the application patrol policy for the application. The NXC examines these first
eight packets to identify the application.
The second approach is called service ports. The NXC uses only OSI level-4
information, such as ports, to identify what application is using the connection.
This approach is available in case the NXC identifies a lot of "false positives" for a
particular application.
266
NXC5200 User's Guide

Advertisement

Table of Contents
loading

This manual is also suitable for:

Nxc5200 - v2.20

Table of Contents