Chapter 24 Firewall
ZyWALL USG 300 User’s Guide
458
Firewall and Application Patrol
To use a service, make sure both the firewall and application patrol allow the
service’s packets to go through the ZyWALL. The ZyWALL checks the firewall rules
before the application patrol rules for traffic going through the ZyWALL.
Firewall and VPN Traffic
After you create a VPN tunnel and add it to a zone, you can set the firewall rules
applied to VPN traffic. If you add a VPN tunnel to an existing zone (the LAN zone
for example), you can configure a new LAN to LAN firewall rule or use intra-zone
traffic blocking to allow or block VPN traffic transmitting between the VPN tunnel
and other interfaces in the LAN zone. If you add the VPN tunnel to a new zone (the
VPN zone for example), you can configure rules for VPN traffic between the VPN
zone and other zones or
From VPN To-ZyWALL
rules for VPN traffic destined for
the ZyWALL.
Session Limits
Accessing the ZyWALL or network resources through the ZyWALL requires a NAT
session and corresponding firewall session. Peer to peer applications, such as file
sharing applications, may use a large number of NAT sessions. A single client
could use all of the available NAT sessions and prevent others from connecting to
or through the ZyWALL. The ZyWALL lets you limit the number of concurrent NAT/
firewall sessions a client can use.
Finding Out More
• See
for related information on the
Firewall
screens.
• See
for an example of creating firewall rules as part
of configuring user-aware access control (
).
• See
for an example of creating a firewall rule to
allow H.323 traffic from the WAN to the LAN.
• See
for an example of creating a firewall rule to
allow web traffic from the WAN to a server on the DMZ.
• See
for an example of creating firewall rules to
allow SIP traffic for an IPPBX or SIP server on the DMZ.
24.1.3 Firewall Rule Example Applications
Suppose that your company decides to block all of the LAN users from using IRC
(Internet Relay Chat) through the Internet. To do this, you would configure a LAN
to WAN firewall rule that blocks IRC traffic from any source IP address from going
to any destination address. You do not need to specify a schedule since you need
Содержание Unified Security Gateway ZyWALL 300
Страница 2: ......
Страница 30: ...Table of Contents ZyWALL USG 300 User s Guide 30 ...
Страница 31: ...31 PART I User s Guide ...
Страница 32: ...32 ...
Страница 38: ...Chapter 1 Introducing the ZyWALL ZyWALL USG 300 User s Guide 38 ...
Страница 46: ...Chapter 2 Features and Applications ZyWALL USG 300 User s Guide 46 ...
Страница 64: ...Chapter 3 Web Configurator ZyWALL USG 300 User s Guide 64 ...
Страница 74: ...Chapter 4 Installation Setup Wizard ZyWALL USG 300 User s Guide 74 ...
Страница 116: ...Chapter 6 Configuration Basics ZyWALL USG 300 User s Guide 116 ...
Страница 128: ...Chapter 7 Tutorials ZyWALL USG 300 User s Guide 128 Figure 73 Configuration Network Interface WLAN Add ...
Страница 184: ...Chapter 7 Tutorials ZyWALL USG 300 User s Guide 184 ...
Страница 221: ...221 PART II Technical Reference ...
Страница 222: ...222 ...
Страница 288: ...Chapter 11 Registration ZyWALL USG 300 User s Guide 288 ...
Страница 303: ...Chapter 13 Interfaces ZyWALL USG 300 User s Guide 303 Figure 269 Configuration Network Interface Ethernet Edit ...
Страница 320: ...Chapter 13 Interfaces ZyWALL USG 300 User s Guide 320 Figure 275 Configuration Network Interface Cellular Add ...
Страница 330: ...Chapter 13 Interfaces ZyWALL USG 300 User s Guide 330 Figure 278 Configuration Network Interface WLAN Add No Security ...
Страница 345: ...Chapter 13 Interfaces ZyWALL USG 300 User s Guide 345 Figure 286 Configuration Network Interface VLAN Edit ...
Страница 355: ...Chapter 13 Interfaces ZyWALL USG 300 User s Guide 355 Figure 288 Configuration Network Interface Bridge Add ...
Страница 378: ...Chapter 14 Trunks ZyWALL USG 300 User s Guide 378 ...
Страница 394: ...Chapter 15 Policy and Static Routes ZyWALL USG 300 User s Guide 394 ...
Страница 408: ...Chapter 16 Routing Protocols ZyWALL USG 300 User s Guide 408 ...
Страница 428: ...Chapter 19 NAT ZyWALL USG 300 User s Guide 428 ...
Страница 454: ...Chapter 23 Authentication Policy ZyWALL USG 300 User s Guide 454 ...
Страница 472: ...Chapter 24 Firewall ZyWALL USG 300 User s Guide 472 ...
Страница 479: ...Chapter 25 IPSec VPN ZyWALL USG 300 User s Guide 479 Figure 355 Configuration VPN IPSec VPN VPN Connection Edit IKE ...
Страница 490: ...Chapter 25 IPSec VPN ZyWALL USG 300 User s Guide 490 Figure 358 Configuration VPN IPSec VPN VPN Gateway Edit ...
Страница 534: ...Chapter 27 SSL User Screens ZyWALL USG 300 User s Guide 534 ...
Страница 536: ...Chapter 28 SSL User Application Screens ZyWALL USG 300 User s Guide 536 ...
Страница 544: ...Chapter 29 SSL User File Sharing ZyWALL USG 300 User s Guide 544 ...
Страница 638: ...Chapter 35 ADP ZyWALL USG 300 User s Guide 638 Figure 448 Profiles Protocol Anomaly ...
Страница 682: ...Chapter 37 Content Filter Reports ZyWALL USG 300 User s Guide 682 ...
Страница 700: ...Chapter 38 Anti Spam ZyWALL USG 300 User s Guide 700 ...
Страница 722: ...Chapter 39 Device HA ZyWALL USG 300 User s Guide 722 ...
Страница 738: ...Chapter 40 User Group ZyWALL USG 300 User s Guide 738 ...
Страница 744: ...Chapter 41 Addresses ZyWALL USG 300 User s Guide 744 ...
Страница 756: ...Chapter 43 Schedules ZyWALL USG 300 User s Guide 756 ...
Страница 772: ...Chapter 45 Authentication Method ZyWALL USG 300 User s Guide 772 ...
Страница 794: ...Chapter 46 Certificates ZyWALL USG 300 User s Guide 794 ...
Страница 806: ...Chapter 48 SSL Application ZyWALL USG 300 User s Guide 806 ...
Страница 811: ...Chapter 49 Endpoint Security ZyWALL USG 300 User s Guide 811 ...
Страница 866: ...Chapter 50 System ZyWALL USG 300 User s Guide 866 ...
Страница 873: ...Chapter 51 Log and Report ZyWALL USG 300 User s Guide 873 ...
Страница 886: ...Chapter 51 Log and Report ZyWALL USG 300 User s Guide 886 ...
Страница 916: ...Chapter 54 Packet Flow Explore ZyWALL USG 300 User s Guide 916 ...
Страница 918: ...Chapter 55 Reboot ZyWALL USG 300 User s Guide 918 ...
Страница 920: ...Chapter 56 Shutdown ZyWALL USG 300 User s Guide 920 ...
Страница 948: ...Chapter 58 Product Specifications ZyWALL USG 300 User s Guide 948 ...
Страница 1014: ...Appendix A Log Descriptions ZyWALL USG 300 User s Guide 1014 ...
Страница 1124: ...Appendix F Open Software Announcements ZyWALL USG 300 User s Guide 1124 ...
Страница 1156: ...Index ZyWALL USG 300 User s Guide 1156 ...