_______________________________________________________________________________________________________
_____________________________________________________________________________________________________
© Virtual Access 2017
GW7304 Series User Manual
Issue: 1.9
Page 230 of 336
25.2.2
Firewall zone settings
The zone section groups one or more interfaces and serves as a source or destination for
forwardings, rules and redirects. Masquerading (NAT) of outgoing traffic is controlled on
a per-zone basis. To view a zone’s settings, click Edit.
The number of concurrent dynamic/static NAT entries of any kind
(NAT/PAT/DNAT/SNAT) is not limited in any way by software; the only hardware
limitation is the amount of RAM installed on the device.
25.2.2.1
Firewall zone: general settings
Figure 121: The firewall zone general settings
Web Field/UCI/Package Option
Description
Web: name
UCI: firewall.<zone label>.name
Opt: name
Sets the unique zone name. Maximum of 11 characters allowed.
Note: the zone label is obtained by using the 'uci show firewall'
command and is of the format '@zone[x]' where x is an integer
starting at 0.
Web: Input
UCI: firewall.<zone label>.input
Opt: input
Default policy for incoming zone traffic. Incoming traffic is traffic
entering the router through an interface selected in the 'Covered
Networks' option for this zone.
Accept
Accepted packets pass through the
firewall.
Reject
Rejected packets are blocked by the
firewall and ICMP message is returned to
the source host.
Drop
Dropped packets are blocked by the
firewall.