P-2608HWL-Dx Series User’s Guide
194
Chapter 15 Firewalls
The previous figure shows the ZyXEL Device’s default firewall rules in action as well as
demonstrates how stateful inspection works. User A can initiate a Telnet session from within
the LAN and responses to this request are allowed. However other Telnet traffic initiated from
the WAN is blocked.
15.5.1 Stateful Inspection Process
In this example, the following sequence of events occurs when a TCP packet leaves the LAN
network through the firewall's WAN interface. The TCP packet is the first in a session, and the
packet's application layer protocol is configured for a firewall rule inspection:
1
The packet travels from the firewall's LAN to the WAN.
2
The packet is evaluated against the interface's existing outbound access list, and the
packet is permitted (a denied packet would simply be dropped at this point).
3
The packet is inspected by a firewall rule to determine and record information about the
state of the packet's connection. This information is recorded in a new state table entry
created for the new connection. If there is not a firewall rule for this packet and it is not an
attack, then the settings in the
Firewall General
screen determine the action for this
packet.
4
Based on the obtained state information, a firewall rule creates a temporary access list
entry that is inserted at the beginning of the WAN interface's inbound extended access
list. This temporary access list entry is designed to permit inbound packets of the same
connection as the outbound packet just inspected.
5
The outbound packet is forwarded out through the interface.
6
Later, an inbound packet reaches the interface. This packet is part of the connection
previously established with the outbound packet. The inbound packet is evaluated against
the inbound access list, and is permitted because of the temporary access list entry
previously created.
7
The packet is inspected by a firewall rule, and the connection's state table entry is updated
as necessary. Based on the updated state information, the inbound extended access list
temporary entries might be modified, in order to permit only packets that are valid for the
current state of the connection.
8
Any additional inbound or outbound packets that belong to the connection are inspected
to update the state table entry and to modify the temporary inbound access list entries as
required, and are forwarded through the interface.
9
When the connection terminates or times out, the connection's state table entry is deleted
and the connection's temporary inbound access list entries are deleted.
15.5.2 Stateful Inspection on Your ZyXEL Device
Additional rules may be defined to extend or override the default rules. For example, a rule
may be created which will:
• Block all traffic of a certain type, such as IRC (Internet Relay Chat), from the LAN to the
Internet.
Содержание P-2608HWL-D1
Страница 1: ...P 2608HWL Dx Series 802 11g Wireless ADSL2 VoIP IAD User s Guide Version 3 40 10 2006 Edition 1 ...
Страница 2: ......
Страница 7: ...P 2608HWL Dx Series User s Guide Safety Warnings 7 This product is recyclable Dispose of it properly ...
Страница 24: ...P 2608HWL Dx Series User s Guide 24 Table of Contents ...
Страница 32: ...P 2608HWL Dx Series User s Guide 32 List of Figures ...
Страница 38: ...P 2608HWL Dx Series User s Guide 38 List of Tables ...
Страница 44: ...P 2608HWL Dx Series User s Guide 44 Chapter 1 Getting To Know the ZyXEL Device ...
Страница 66: ...P 2608HWL Dx Series User s Guide 66 Chapter 3 Internet and Wireless Setup Wizard ...
Страница 72: ...P 2608HWL Dx Series User s Guide 72 Chapter 4 VoIP Wizard And Example ...
Страница 78: ...P 2608HWL Dx Series User s Guide 78 Chapter 5 Bandwidth Management Wizard ...
Страница 88: ...P 2608HWL Dx Series User s Guide 88 Chapter 6 Status Screens ...
Страница 118: ...P 2608HWL Dx Series User s Guide 118 Chapter 8 LAN Setup ...
Страница 138: ...P 2608HWL Dx Series User s Guide 138 Chapter 9 Wireless LAN ...
Страница 166: ...P 2608HWL Dx Series User s Guide 166 Chapter 11 SIP ...
Страница 176: ...P 2608HWL Dx Series User s Guide 176 Chapter 12 Phone ...
Страница 184: ...P 2608HWL Dx Series User s Guide 184 Chapter 13 Phone Book ...
Страница 206: ...P 2608HWL Dx Series User s Guide 206 Chapter 16 Firewall Configuration Figure 107 Firewall Edit Rule ...
Страница 220: ...P 2608HWL Dx Series User s Guide 220 Chapter 17 Content Filtering ...
Страница 257: ...P 2608HWL Dx Series User s Guide Chapter 19 Certificates 257 Figure 138 My Certificate Details ...
Страница 268: ...P 2608HWL Dx Series User s Guide 268 Chapter 19 Certificates Figure 146 Trusted Remote Host Details ...
Страница 276: ...P 2608HWL Dx Series User s Guide 276 Chapter 20 Static Route ...
Страница 288: ...P 2608HWL Dx Series User s Guide 288 Chapter 21 Bandwidth Management ...
Страница 292: ...P 2608HWL Dx Series User s Guide 292 Chapter 22 Dynamic DNS Setup ...
Страница 306: ...P 2608HWL Dx Series User s Guide 306 Chapter 23 Remote Management Configuration ...
Страница 318: ...P 2608HWL Dx Series User s Guide 318 Chapter 24 Universal Plug and Play UPnP ...
Страница 324: ...P 2608HWL Dx Series User s Guide 324 Chapter 25 System ...
Страница 344: ...P 2608HWL Dx Series User s Guide 344 Chapter 27 Tools ...
Страница 348: ...P 2608HWL Dx Series User s Guide 348 Chapter 28 Diagnostic ...
Страница 360: ...P 2608HWL Dx Series User s Guide 360 Chapter 29 Troubleshooting ...
Страница 378: ...P 2608HWL Dx Series User s Guide 378 Appendix B Setting up Your Computer s IP Address ...
Страница 402: ...P 2608HWL Dx Series User s Guide 402 Appendix F Triangle Route ...
Страница 440: ...P 2608HWL Dx Series User s Guide 440 Appendix H Internal SPTGEN ...