• The DMZ zone contains the dmz interface (physical port P6). The DMZ zone has
servers that are available to the public. The dmz interface uses private IP
address 192.168.3.1 and the connected devices use private IP addresses in the
192.168.3.2 to 192.168.3.254 range.
6.3 Terminology in the ZyWALL
This section highlights some terminology or organization for ZLD-based ZyWALLs.
Table 15 ZLD ZyWALL Terminology
FEATURE / TERM
IP alias
Gateway policy
Network policy (IPSec SA)
Source NAT (SNAT)
Trigger port, port triggering
Address mapping
Address mapping (VPN)
Interface bandwidth management
(outbound)
General bandwidth management
6.4 Packet Flow
Here is the order in which the ZyWALL applies its features and checks.
ZyWALL USG 20/20W User's Guide
Chapter 6 Configuration Basics
ZLD ZYWALL FEATURE / TERM
Virtual interface
VPN gateway
VPN connection
Policy route
Policy route
Policy route
IPSec VPN
Interface
Policy route
91