Chapter 12 Firewall
P-2304R-P1 Series User’s Guide
139
Blocked
LAN-to-WAN
packets are considered alerts. Alerts are “higher priority logs” that
include system errors, attacks and attempted access to blocked web sites. Alerts appear in red
in the
View Log
screen. You may choose to have alerts e-mailed immediately in the
Log
Settings
screen.
LAN-to-LAN/ZyXEL Device means the LAN to the ZyXEL Device LAN interface. This is
always allowed, as this is how you manage the ZyXEL Device from your local computer.
12.1.4.2 WAN-to-LAN rules
WAN-to-LAN
rules are Internet to your local network firewall rules. The default is to block
all traffic from the Internet to your local network.
How can you forward certain WAN to LAN traffic? You may allow traffic originating from
the WAN to be forwarded to the LAN by:
• Configuring NAT port forwarding rules.
• Configuring
One-to-One
and
Many-One-to-One
NAT mapping rules in the web
configurator
Address Mapping
screen.
• Configuring
WAN
or
LAN & WAN
access for services in the
Remote Management
screens. When you allow remote management from the WAN, you are actually
configuring WAN-to-WAN/ZyXEL Device firewall rules. WAN-to-WAN/ZyXEL
Device firewall rules are Internet to the ZyXEL Device WAN interface firewall rules. The
default is to block all such traffic. When you decide what WAN-to-LAN packets to log,
you are in fact deciding what
WAN-to-LAN
and WAN-to-WAN/ZyXEL Device packets
to log.
Forwarded
WAN-to-LAN
packets are not considered alerts.
12.2 Triangle Route
When the firewall is on, your ZyXEL Device acts as a secure gateway between your LAN and
the Internet. In an ideal network topology, all incoming and outgoing network traffic passes
through the ZyXEL Device to protect your LAN against attacks.
Figure 69
Ideal Firewall Setup
12.2.1 The “Triangle Route” Problem
A traffic route is a path for sending or receiving data packets between two Ethernet devices.
You may have more than one connection to the Internet (through one or more ISPs). If an
alternate gateway is on the LAN (and its IP address is in the same subnet as the ZyXEL
Device’s LAN IP address), the “triangle route” (also called asymmetrical route) problem may
occur. The steps below describe the “triangle route” problem.
Содержание P-2304R
Страница 1: ...www zyxel com P 2304R P1 Series VoIP Station Gateway User s Guide Version 3 60 10 2006 Edition 1...
Страница 2: ......
Страница 8: ...Contents Overview P 2304R P1 Series User s Guide 8...
Страница 26: ...26...
Страница 32: ...Chapter 1 Introducing the ZyXEL Device P 2304R P1 Series User s Guide 32...
Страница 40: ...Chapter 2 Introducing the Web Configurator P 2304R P1 Series User s Guide 40...
Страница 73: ...73 PART II Network WAN 75 LAN 85 NAT 97...
Страница 74: ...74...
Страница 105: ...105 PART III VoIP SIP 107 Phone 121 Phone Book 129...
Страница 106: ...106...
Страница 116: ...Chapter 9 SIP P 2304R P1 Series User s Guide 116 Figure 60 VoIP SIP SIP Settings Advanced...
Страница 128: ...Chapter 10 Phone P 2304R P1 Series User s Guide 128...
Страница 134: ...Chapter 11 Phone Book P 2304R P1 Series User s Guide 134...
Страница 135: ...135 PART IV Security and Management Firewall 137 Content Filter 145 Static Route 149 Bandwidth MGMT 153 Remote MGMT 165...
Страница 136: ...136...
Страница 144: ...Chapter 12 Firewall P 2304R P1 Series User s Guide 144...
Страница 148: ...Chapter 13 Content Filter P 2304R P1 Series User s Guide 148...
Страница 152: ...Chapter 14 Static Route P 2304R P1 Series User s Guide 152...
Страница 173: ...173 PART V Maintenance and Troubleshooting UPnP 175 System 187 Logs 195 Tools 209 Troubleshooting 215...
Страница 174: ...174...
Страница 186: ...Chapter 17 UPnP P 2304R P1 Series User s Guide 186...
Страница 194: ...Chapter 18 System P 2304R P1 Series User s Guide 194...
Страница 208: ...Chapter 19 Logs P 2304R P1 Series User s Guide 208...
Страница 220: ...Chapter 21 Troubleshooting P 2304R P1 Series User s Guide 220...
Страница 222: ...222...
Страница 228: ...Appendix A Product Specifications P 2304R P1 Series User s Guide 228...
Страница 258: ...Appendix E SIP Passthrough P 2304R P1 Series User s Guide 258...
Страница 290: ...Appendix I Legal Information P 2304R P1 Series User s Guide 290...