Application Patrol - ZyXEL Communications ZyWall USG 50-H Series User Manual

Unified security gateway
Table of Contents

Advertisement

To-ZyWALL firewall rules control access to the ZyWALL. Configure to-ZyWALL firewall
rules for remote management. By default, the firewall allows HTTP management access from
the LAN zones and HTTPS management access from the LAN and WAN zones. The
ZyWALL drops packets from the WAN or DMZ zone to the ZyWALL itself, except for VPN
traffic.
MENU ITEM(S)
PREREQUISITES
Example: Suppose you have a SIP proxy server connected to the DMZ zone for VoIP calls.
You could configure a firewall rule to allow VoIP sessions from the SIP proxy server on DMZ
to LAN1 so VoIP users on LAN1 can receive calls.
1 Create a VoIP service object for UDP port 5060 traffic (Object > Service).
2 Create an address object for the VoIP server (Object > Address).
3 Click Firewall to go to the firewall configuration.
4 Select from the DMZ zone to the LAN1 zone, and add a firewall rule using the items
you have configured.
• You don't need to specify the schedule or the user.
• In the Source field, select the address object of the VoIP server.
• You don't need to specify the destination address.
• Leave the Access field set to Allow and the Log field set to No.
The ZyWALL checks the firewall rules in order. Make sure each rule is in the
correct place in the sequence.

5.4.12 Application Patrol

Use application patrol to control which individuals can use which services through the
ZyWALL (and when they can do so). You can also specify allowed amounts of bandwidth and
priorities.
MENU ITEM(S)
PREREQUISITES
Example: Suppose you want to allow vice president Bob to use BitTorrent and block
everyone else from using it.
1 Create a user account for Bob (User/Group).
2 Click AppPatrol/BWM > Peer to Peer to go to the application patrol configuration
screen. Click the BitTorrent application patrol entry's Edit icon.
• Set the default policy's access to Drop.
• Add another policy.
• Select the user account that you created for Bob.
• You can leave the source, destination and log settings at the default.
ZyWALL USG 50-H User's Guide
Firewall
Zones, schedules, users, user groups, addresses (source, destination), address
groups (source, destination), services, service groups
AppPatrol
Zones, Schedules, users, user groups, addresses (source, destination), address
groups (source, destination). These are only used as criteria in exceptions and
conditions.
Chapter 5 Configuration Basics
87

Advertisement

Table of Contents
loading

Table of Contents