Chapter 7 Firewalls
P-660R-F1 Series User’s Guide
90
The following table describes the labels in this screen.
7.3 The Firewall Rule Screen
Note: The ordering of your rules is very important as rules are applied in turn.
Table 31
Security > Firewall > General
LABEL
DESCRIPTION
Active Firewall
Select this check box to activate the firewall. The ZyXEL Device performs access
control and protects against Denial of Service (DoS) attacks when the firewall is
activated.
Bypass Triangle
Route
If an alternate gateway on the LAN has an IP address in the same subnet as the
ZyXEL Device’s LAN IP address, return traffic may not go through the ZyXEL
Device. This is called an asymmetrical or “triangle” route. This causes the ZyXEL
Device to reset the connection, as the connection has not been acknowledged.
Select this check box to have the ZyXEL Device permit the use of asymmetrical
route topology on the network (not reset the connection).
Note: Allowing asymmetrical routes may let traffic from the WAN go directly to the
LAN without passing through the ZyXEL Device. A better solution is to use
IP alias to put the ZyXEL Device and the backup gateway on separate
subnets. See
for an example.
Packet Direction
This is the direction of travel of packets (
LAN to Router
,
LAN to WAN
,
WAN to
Router
,
WAN to LAN)
.
Firewall rules are grouped based on the direction of travel of packets to which
they apply. For example,
LAN to Router
means packets traveling from a
computer/subnet on the LAN to the ZyXEL Device itself.
Default Action
Use the drop-down list boxes to select the default action that the firewall is to
take on packets that are traveling in the selected direction and do not match any
of the firewall rules.
Select
Drop
to silently discard the packets without sending a TCP reset packet or
an ICMP destination-unreachable message to the sender.
Select
Reject
to deny the packets and send a TCP reset packet (for a TCP
packet) or an ICMP destination-unreachable message (for a UDP packet) to the
sender.
Select
Permit
to allow the passage of the packets.
Log
Select the check box to create a log (when the above action is taken) for packets
that are traveling in the selected direction and do not match any of your
customized rules.
Expand...
Click this to display more information.
Basic...
Click this to display less information.
Apply
Click this to save your changes.
Cancel
Click this to restore your previously saved settings.
Содержание P-660R-F1 series
Страница 2: ......
Страница 8: ...Certifications P 660R F1 Series User s Guide 8 ...
Страница 16: ...P 660R F1 Series User s Guide 16 ...
Страница 18: ...P 660R F1 Series User s Guide 18 ...
Страница 62: ...Chapter 4 WAN Setup P 660R F1 Series User s Guide 62 ...
Страница 104: ...Chapter 7 Firewalls P 660R F1 Series User s Guide 104 ...
Страница 140: ...Chapter 9 Certificates P 660R F1 Series User s Guide 140 ...
Страница 144: ...Chapter 10 Static Route P 660R F1 Series User s Guide 144 ...
Страница 162: ...Chapter 12 Dynamic DNS Setup P 660R F1 Series User s Guide 162 ...
Страница 190: ...Chapter 15 System P 660R F1 Series User s Guide 190 ...
Страница 204: ...Chapter 16 Logs P 660R F1 Series User s Guide 204 ...
Страница 212: ...Chapter 18 Diagnostic P 660R F1 Series User s Guide 212 ...
Страница 216: ...Chapter 19 Troubleshooting P 660R F1 Series User s Guide 216 ...
Страница 220: ...P 660R F1 Series User s Guide 220 ...
Страница 222: ...P 660R F1 Series User s Guide 222 ...
Страница 246: ...P 660R F1 Series User s Guide 246 ...
Страница 250: ...P 660R F1 Series User s Guide 250 ...
Страница 258: ...P 660R F1 Series User s Guide 258 3 Click OK to close the window Figure 172 Java Sun ...
Страница 266: ...P 660R F1 Series User s Guide 266 ...
Страница 267: ...P 660R F1 Series User s Guide 267 ...
Страница 268: ...P 660R F1 Series User s Guide 268 ...