![ZyXEL Communications G-2000 Plus V2 Скачать руководство пользователя страница 141](http://html1.mh-extra.com/html/zyxel-communications/g-2000-plus-v2/g-2000-plus-v2_user-manual_945995141.webp)
ZyXEL G-2000 Plus v2 User’s Guide
Chapter 10 Firewalls
141
3
The firewall inspects packets to determine and record information about the state of the
packet's connection. This information is recorded in a new state table entry created for the
new connection. If there is not a firewall rule for this packet and it is not an attack, then
the
setting in the
Firewall Default Rule
screen determines the action for this packet.
4
Based on the obtained state information, a firewall rule creates a temporary access list
entry that is inserted at the beginning of the WAN interface's inbound extended access
list. This temporary access list entry is designed to permit inbound packets of the same
connection as the outbound packet just inspected.
5
The outbound packet is forwarded out through the interface.
6
Later, an inbound packet reaches the interface. This packet is part of the connection
previously established with the outbound packet. The inbound packet is evaluated against
the inbound access list, and is permitted because of the temporary access list entry
previously created.
7
The packet is inspected by a firewall rule, and the connection's state table entry is updated
as necessary. Based on the updated state information, the inbound extended access list
temporary entries might be modified, in order to permit only packets that are valid for the
current state of the connection.
8
Any additional inbound or outbound packets that belong to the connection are inspected
to update the state table entry and to modify the temporary inbound access list entries as
required, and are forwarded through the interface.
9
When the connection terminates or times out, the connection's state table entry is deleted
and the connection's temporary inbound access list entries are deleted.
10.5.2 Stateful Inspection and the ZyXEL device
Additional rules may be defined to extend or override the default rules. For example, a rule
may be created which will:
1
Block all traffic of a certain type, such as IRC (Internet Relay Chat), from the LAN to the
Internet.
2
Allow certain types of traffic from the Internet to specific hosts on the LAN.
3
Allow access to a Web server to everyone but competitors.
4
Restrict use of certain protocols, such as Telnet, to authorized users on the LAN.
These custom rules work by evaluating the network traffic’s Source IP address, Destination IP
address, IP protocol type, and comparing these to rules set by the administrator.
Note:
The ability to define firewall rules is a very powerful tool. Using custom rules, it
is possible to disable all firewall protection or block all access to the Internet.
Use extreme caution when creating or deleting firewall rules. Test changes
after creating them to make sure they work correctly.
Below is a brief technical description of how these connections are tracked. Connections may
either be defined by the upper protocols (for instance, TCP), or by the ZyXEL device itself (as
with the "virtual connections" created for UDP and ICMP).
Содержание G-2000 Plus V2
Страница 1: ...ZyXEL G 2000 Plus v2 4 port Wireless Router User s Guide Version 3 60 Edition 1 2 2006...
Страница 2: ......
Страница 10: ...ZyXEL G 2000 Plus v2 User s Guide 10 Customer Support...
Страница 24: ...ZyXEL G 2000 Plus v2 User s Guide 24 Table of Contents...
Страница 50: ...ZyXEL G 2000 Plus v2 User s Guide 50 Chapter 2 Introducing the Web Configurator...
Страница 66: ...ZyXEL G 2000 Plus v2 User s Guide 66 Chapter 3 Wizard Setup...
Страница 100: ...ZyXEL G 2000 Plus v2 User s Guide 100 Chapter 6 Wireless LAN...
Страница 112: ...ZyXEL G 2000 Plus v2 User s Guide 112 Chapter 7 WAN...
Страница 153: ...ZyXEL G 2000 Plus v2 User s Guide Chapter 11 Firewall Screens 153 Figure 59 Creating Editing A Firewall Rule...
Страница 158: ...ZyXEL G 2000 Plus v2 User s Guide 158 Chapter 11 Firewall Screens Figure 64 My Service Rule Configuration...
Страница 162: ...ZyXEL G 2000 Plus v2 User s Guide 162 Chapter 11 Firewall Screens...
Страница 166: ...ZyXEL G 2000 Plus v2 User s Guide 166 Chapter 12 Content Filtering...
Страница 178: ...ZyXEL G 2000 Plus v2 User s Guide 178 Chapter 13 Remote Management Screens...
Страница 188: ...ZyXEL G 2000 Plus v2 User s Guide 188 Chapter 14 UPnP...
Страница 198: ...ZyXEL G 2000 Plus v2 User s Guide 198 Chapter 15 Internal RADIUS Server...
Страница 205: ...ZyXEL G 2000 Plus v2 User s Guide Chapter 16 Certificates 205 Figure 84 My Certificate Create...
Страница 219: ...ZyXEL G 2000 Plus v2 User s Guide Chapter 17 Log Screens 219 Figure 90 Log Settings...
Страница 234: ...ZyXEL G 2000 Plus v2 User s Guide 234 Chapter 18 Maintenance Figure 105 Restart Screen...
Страница 262: ...ZyXEL G 2000 Plus v2 User s Guide 262 Chapter 23 Internet Access...
Страница 272: ...ZyXEL G 2000 Plus v2 User s Guide 272 Chapter 24 Remote Node Configuration...
Страница 322: ...ZyXEL G 2000 Plus v2 User s Guide 322 Chapter 31 System Security...
Страница 334: ...ZyXEL G 2000 Plus v2 User s Guide 334 Chapter 32 System Information and Diagnosis...
Страница 346: ...ZyXEL G 2000 Plus v2 User s Guide 346 Chapter 33 Firmware and Configuration File Maintenance...
Страница 354: ...ZyXEL G 2000 Plus v2 User s Guide 354 Chapter 34 System Maintenance and Information...
Страница 368: ...ZyXEL G 2000 Plus v2 User s Guide 368...
Страница 380: ...ZyXEL G 2000 Plus v2 User s Guide 380...
Страница 384: ...ZyXEL G 2000 Plus v2 User s Guide 384...
Страница 392: ...ZyXEL G 2000 Plus v2 User s Guide 392...
Страница 394: ...ZyXEL G 2000 Plus v2 User s Guide 394...
Страница 415: ...ZyXEL G 2000 Plus v2 User s Guide 415 Figure 232 Sequences for PEAP MS CHAP V2 Authentication...
Страница 416: ...ZyXEL G 2000 Plus v2 User s Guide 416...
Страница 426: ...ZyXEL G 2000 Plus v2 User s Guide 426...