Chapter 10 Firewall Configuration
P-660HW-Dx User’s Guide
156
"
If you configure firewall rules without a good understanding of how they work,
you might inadvertently introduce security risks to the firewall and to the
protected network. Make sure you test your rules after you configure them.
For example, you may create rules to:
• Block certain types of traffic, such as IRC (Internet Relay Chat), from the LAN to the
Internet.
• Allow certain types of traffic, such as Lotus Notes database synchronization, from specific
hosts on the Internet to specific hosts on the LAN.
• Allow everyone except your competitors to access a Web server.
• Restrict use of certain protocols, such as Telnet, to authorized users on the LAN.
These custom rules work by comparing the Source IP address, Destination IP address and IP
protocol type of network traffic to rules set by the administrator. Your customized rules take
precedence and override the ZyXEL Device’s default rules.
10.3 Rule Logic Overview
"
Study these points carefully before configuring rules.
10.3.1 Rule Checklist
State the intent of the rule. For example, “This restricts all IRC access from the LAN to the
Internet.” Or, “This allows a remote Lotus Notes server to synchronize over the Internet to an
inside Notes server.”
1
Is the intent of the rule to forward or block traffic?
2
What direction of traffic does the rule apply to?
3
What IP services will be affected?
4
What computers on the LAN are to be affected (if any)?
5
What computers on the Internet will be affected? The more specific, the better. For
example, if traffic is being allowed from the Internet to the LAN, it is better to allow
only certain machines on the Internet to access the LAN.
10.3.2 Security Ramifications
1
Once the logic of the rule has been defined, it is critical to consider the security
ramifications created by the rule:
2
Does this rule stop LAN users from accessing critical resources on the Internet? For
example, if IRC is blocked, are there users that require this service?
Summary of Contents for P-660HW-DX
Page 2: ......
Page 7: ...Safety Warnings P 660HW Dx User s Guide 7...
Page 8: ...Safety Warnings P 660HW Dx User s Guide 8...
Page 10: ...Contents Overview P 660HW Dx User s Guide 10...
Page 20: ...Table of Contents P 660HW Dx User s Guide 20...
Page 26: ...List of Figures P 660HW Dx User s Guide 26...
Page 31: ...31 PART I Introduction Introducing the ZyXEL Device 33 Introducing the Web Configurator 37...
Page 32: ...32...
Page 50: ...Chapter 2 Introducing the Web Configurator P 660HW Dx User s Guide 50...
Page 51: ...51 PART II Wizards Wizard Setup for Internet Access 53 Bandwidth Management Wizard 67...
Page 52: ...52...
Page 66: ...Chapter 3 Wizard Setup for Internet Access P 660HW Dx User s Guide 66...
Page 72: ...Chapter 4 Bandwidth Management Wizard P 660HW Dx User s Guide 72...
Page 74: ...74...
Page 92: ...Chapter 5 WAN Setup P 660HW Dx User s Guide 92...
Page 141: ...141 PART IV Security Firewalls 143 Firewall Configuration 155 Content Filtering 177...
Page 142: ...142...
Page 162: ...Chapter 10 Firewall Configuration P 660HW Dx User s Guide 162 Figure 88 Firewall Edit Rule...
Page 176: ...Chapter 10 Firewall Configuration P 660HW Dx User s Guide 176...
Page 180: ...Chapter 11 Content Filtering P 660HW Dx User s Guide 180...
Page 182: ...182...
Page 186: ...Chapter 12 Static Route P 660HW Dx User s Guide 186...
Page 202: ...Chapter 14 Dynamic DNS Setup P 660HW Dx User s Guide 202...
Page 224: ...Chapter 16 Universal Plug and Play UPnP P 660HW Dx User s Guide 224...
Page 226: ...226...
Page 232: ...Chapter 17 System P 660HW Dx User s Guide 232...
Page 250: ...Chapter 18 Logs P 660HW Dx User s Guide 250...
Page 256: ...Chapter 19 Tools P 660HW Dx User s Guide 256...
Page 264: ...264...
Page 330: ...Appendix F Internal SPTGEN P 660HW Dx User s Guide 330...
Page 332: ...Appendix G Command Interpreter P 660HW Dx User s Guide 332...
Page 344: ...Appendix J Splitters and Microfilters P 660HW Dx User s Guide 344...
Page 350: ...Appendix L Legal Information P 660HW Dx User s Guide 350...
Page 356: ...Appendix M Customer Support P 660HW Dx User s Guide 356...
Page 364: ...Index P 660HW Dx User s Guide 364...