What You Need To Know About The Firewall - ZyXEL Communications ZyWall USG 50-H Series User Manual

Unified security gateway
Table of Contents

Advertisement

Chapter 18 Firewall

18.1.2 What You Need to Know About the Firewall

Stateful Inspection
The ZyWALL has a stateful inspection firewall. The ZyWALL restricts access by screening
data packets against defined access rules. It also inspects sessions. For example, traffic from
one zone is not allowed unless it is initiated by a computer in another zone first.
Zones
A zone is a group of interfaces or VPN tunnels. Group the ZyWALL's interfaces into different
zones based on your needs. You can configure firewall rules for data passing between zones or
even between interfaces and/or VPN tunnels in a zone.
Default Firewall Behavior
Firewall rules are grouped based on the direction of travel of packets to which they apply.
Here are the default firewall behavior for traffic going through the ZyWALL. By default the
ZyWALL forces authentication for WLAN users. Un-authenticated WLAN users can only
access the WAN.
Table 107 Default Firewall Rules
FROM ZONE TO ZONE
From ANY to ANY
From WAN to LAN
From WAN to WLAN
From WAN to ZyWALL
(Default services)
From WAN to ZyWALL
From DMZ to LAN
From DMZ to WLAN
From DMZ to ZyWALL
(Default services)
From DMZ to ZyWALL
From WLAN to LAN
From WLAN to WAN (guest) Traffic from the WLAN to the WAN (guest) is allowed.
From WLAN to WAN (DNS)
From WLAN to WAN
From WLAN to DMZ
From WLAN to ZyWALL
To-ZyWALL Rules
Rules with ZyWALL as the To Zone apply to traffic going to the ZyWALL itself. By default:
290
STATEFUL PACKET INSPECTION
Traffic that does not match any firewall rule is allowed. This
includes traffic to or from interfaces or VPN tunnels that are not
assigned to any zone (extra-zone traffic).
Traffic from the WAN to the LAN is denied.
Traffic from the WAN to the WLAN is denied.
Traffic from the WAN to the ZyWALL (default services) is
allowed. Default services are traffic types described in
ZyWALL Rules on page
290.
Traffic from the WAN to the ZyWALL itself is denied except for
the traffic types described in
Traffic from the DMZ to the LAN is denied.
Traffic from the DMZ to the WLAN is denied.
Traffic from the DMZ to the ZyWALL (default services) is
allowed. Default services are traffic types described in
ZyWALL Rules on page
290.
Traffic from the DMZ to the ZyWALL itself is denied except for
the traffic types described in
Traffic WLAN to LAN is rejected.
Traffic from the WLAN to the WAN (DNS) is allowed.
Traffic from WLAN to WAN is rejected.
Traffic from WLAN to DMZ is rejected.
Traffic from the DMZ to the ZyWALL is denied.
To-
To-ZyWALL Rules on page
To-
To-ZyWALL Rules on page
ZyWALL USG 50-H User's Guide
290.
290.

Advertisement

Table of Contents
loading

Table of Contents