Alerts; Asymmetrical Routes; Table 86 Limited Lan To Wan Irc Traffic Example 1; Table 87 Limited Lan To Wan Irc Traffic Example 2 - ZyXEL Communications Unified Security Gateway ZyWALL 1000 User Manual

Unified security gateway
Hide thumbs Also See for Unified Security Gateway ZyWALL 1000:
Table of Contents

Advertisement

Chapter 19 Firewall
Your firewall would have the following configuration.

Table 86 Limited LAN to WAN IRC Traffic Example 1

#
1
2
Default
• The first row allows the LAN computer at IP address 192.168.1.7 to access the IRC
service on the WAN.
• The second row blocks LAN access to the IRC service on the WAN.
• The third row is (still) the firewall's default policy of allowing all traffic from the LAN to
go to the WAN.
Alternatively, you configure a LAN to WAN rule with the CEO's user name (say CEO) to
allow IRC traffic from any source IP address to go to any destination address.
Your firewall would have the following configuration.

Table 87 Limited LAN to WAN IRC Traffic Example 2

#
1
2
Default
• The first row allows any LAN computer to access the IRC service on the WAN by logging
into the ZyWALL with the CEO's user name.
• The second row blocks LAN access to the IRC service on the WAN.
• The third row is (still) the firewall's default policy of allowing all traffic from the LAN to
go to the WAN.
The rule for the CEO must come before the rule that blocks all LAN to WAN IRC traffic. If
the rule that blocks all LAN to WAN IRC traffic came first, the CEO's IRC traffic would
match that rule and the ZyWALL would drop it and not check any other firewall rules.

19.4 Alerts

You can choose to generate an alert or log when a rule is matched and have the ZyWALL send
an immediate e-mail message to you. Otherwise, see the logs created (for the categories you
specified) in the View Log screen. Refer to the chapter on logs for details.

19.5 Asymmetrical Routes

If an alternate gateway on the LAN has an IP address in the same subnet as the ZyWALL's
LAN IP address, return traffic may not go through the ZyWALL. This is called an
asymmetrical or "triangle" route. This causes the ZyWALL to reset the connection, as the
connection has not been acknowledged.
282
DESTINATIO
USER
SOURCE
N
Any
192.168.1.7
Any
Any
Any
Any
Any
Any
Any
DESTINATIO
USER
SOURCE
N
CEO
Any
Any
Any
Any
Any
Any
Any
Any
SCHEDULE
SERVICE
Any
IRC
Any
IRC
Any
Any
SCHEDULE
SERVICE
Any
IRC
Any
IRC
Any
Any
ZyWALL USG 1000 User's Guide
ACTION
Allow
Deny
Allow
ACTION
Allow
Deny
Allow

Advertisement

Table of Contents
loading

This manual is also suitable for:

Zywall usg 1000

Table of Contents