ZyWALL 10~100 Series Internet Security Gateway
into IP Filter
Filter Active?
Apply SrcAddrMask
to Src Addr
Check Src
IP Addr
Matched
Apply DestAddrMask
to Dest Addr
Check Dest
IP Addr
Matched
IP Protocol
Matched
Check Src &
Dest Port
Matched
Action Matched
Drop
Drop Packet
31-10
Packet
No
Yes
Not Matched
Not Matched
Check
Not Matched
Not Matched
More?
Yes
No
Check Next Rule
Forward
Figure 31-7 Executing an IP Filter
Check Next Rule
Check Next Rule
Action Not Matched
Drop
Forward
Accept Packet
Filter Configuration