Configuring A Filter Rule; Table 246 Abbreviations Used In The Filter Rules Summary Menu; Table 247 Rule Abbreviations Used - ZyXEL Communications ZYWALL 35 User Manual

Internet security appliance
Hide thumbs Also See for ZYWALL 35:
Table of Contents

Advertisement

Table 246 Abbreviations Used in the Filter Rules Summary Menu

FIELD
A
Type
Filter Rules
M
m
n
The protocol dependent filter rules abbreviation are listed as follows:

Table 247 Rule Abbreviations Used

ABBREVIATION
IP
Pr
SA
SP
DA
DP
GEN
Off
Len
Refer to the next section for information on configuring the filter rules.

45.2.1 Configuring a Filter Rule

To configure a filter rule, type its number in Menu 21.1.x - Filter Rules Summary and press
[ENTER] to open menu 21.1.x.x for the rule.
To speed up filtering, all rules in a filter set must be of the same class, i.e., protocol filters or
generic filters. The class of a filter set is determined by the first rule that you create. When
applying the filter sets to a port, separate menu fields are provided for protocol and device
filter sets. If you include a protocol filter set in a device filter field or vice versa, the ZyWALL
will warn you and will not allow you to save.
ZyWALL 5/35/70 Series User's Guide
DESCRIPTION
Active: "Y" means the rule is active. "N" means the rule is inactive.
The type of filter rule: "GEN" for Generic, "IP" for TCP/IP.
These parameters are displayed here.
More.
"Y" means there are more rules to check which form a rule chain with the present rule.
An action cannot be taken until the rule chain is complete.
"N" means there are no more rules to check. You can specify an action to be taken i.e.,
forward the packet, drop the packet or check the next rule. For the latter, the next rule is
independent of the rule just checked.
Action Matched.
"F" means to forward the packet immediately and skip checking the remaining rules.
"D" means to drop the packet.
"N" means to check the next rule.
Action Not Matched.
"F" means to forward the packet immediately and skip checking the remaining rules.
"D" means to drop the packet.
"N" means to check the next rule.
DESCRIPTION
Protocol
Source Address
Source Port number
Destination Address
Destination Port number
Offset
Length
Chapter 45 Filter Configuration
689

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents