Alg Technical Reference - ZyXEL Communications ZyWall USG 50-H Series User Manual

Unified security gateway
Table of Contents

Advertisement

Chapter 16 ALG
Table 101 Network > ALG (continued)
LABEL
Enable H.323
Transformations
H.323 Signaling
Port
Additional H.323
Signaling port
for
transformations
Enable FTP ALG Turn on the FTP ALG to detect FTP (File Transfer Program) traffic and help build
Enable FTP
Transformations
FTP Signaling
Port
Additional FTP
Signaling port
for
transformations
Apply
Reset

16.3 ALG Technical Reference

Here is more detailed information about the Application Layer Gateway.
ALG
Some applications cannot operate through NAT (are NAT un-friendly) because they embed IP
addresses and port numbers in their packets' data payload. The ZyWALL examines and uses
IP address and port number information embedded in the VoIP traffic's data stream. When a
device behind the ZyWALL uses an application for which the ZyWALL has VoIP pass
through enabled, the ZyWALL translates the device's private IP address inside the data stream
to a public IP address. It also records session port numbers and allows the related sessions to
go through the firewall so the application's traffic can come in from the WAN to the LAN.
ALG and Trunks
If you send your ALG-managed traffic through an interface trunk and all of the interfaces are
set to active, you can configure routing policies to specify which interface the ALG-managed
traffic uses.
278
DESCRIPTION
Select this to have the ZyWALL modify IP addresses and port numbers embedded
in the H.323 data payload.
You do not need to use this if you have a H.323 device or server that will modify IP
addresses and port numbers embedded in the H.323 data payload.
If you are using a custom TCP port number (not 1720) for H.323 traffic, enter it here.
If you are also using H.323 on an additional TCP port number, enter it here.
FTP sessions through the ZyWALL's NAT. Enabling the FTP ALG also allows you
to use the application patrol to detect FTP traffic and manage the FTP traffic's
bandwidth (see
Chapter 26 on page
Select this option to have the ZyWALL modify IP addresses and port numbers
embedded in the FTP data payload to match the ZyWALL's NAT environment.
Clear this option if you have an FTP device or server that will modify IP addresses
and port numbers embedded in the FTP data payload to match the ZyWALL's NAT
environment.
If you are using a custom TCP port number (not 21) for FTP traffic, enter it here.
If you are also using FTP on an additional TCP port number, enter it here.
Click Apply to save your changes back to the ZyWALL.
Click Reset to begin configuring this screen afresh.
397).
ZyWALL USG 50-H User's Guide

Advertisement

Table of Contents
loading

Table of Contents