Vantage CNM 2.0 User’s Guide
Chapter 7 Configuration > DMZ
96
C
H A P T E R
7
Configuration > DMZ
7.1 DMZ Overview
The DeMilitarized Zone (DMZ) auto-negotiating 10/100 Mbps Ethernet port provides a way
for public servers (Web, e-mail, FTP, etc.) to be visible to the outside world (while still being
protected from DoS (Denial of Service) attacks such as SYN flooding and Ping of Death).
These public servers can also still be accessed from the secure LAN.
By default the firewall allows traffic between the WAN and the DMZ, traffic from the DMZ to
the LAN is denied, and traffic from the LAN to the DMZ is allowed. Internet users can have
access to host servers on the DMZ but no access to the LAN, unless special filter rules
allowing access were configured by the administrator or the user is an authorized remote user.
It is highly recommended that you connect all of your public servers to the DMZ port. If you
have more than one public server, connect a hub to the DMZ port.
It is also highly recommended that you keep all sensitive information off of the public servers
connected to the DMZ port. Store sensitive information on LAN computers.
7.2 DMZ Addresses
You can assign public or private IP addresses to computers connected to the DMZ port.
With public IP addresses, the WAN and DMZ ports must use public IP addresses that are on
separate subnets. See the appendices for information on IP subnetting.
If the DMZ computers use private IP addresses, go to the NAT screen and select SUA Only or
Full Feature in the Network Address Translation field. Configure NAT mapping rules for
the private IP addresses of the computers on the DMZ.
7.3 Configuring DMZ
Select a ZyWALL device and from the Configuration Screen, click DMZ. The screen
appears as shown next.
Содержание VANTAGE CNM 2.0 -
Страница 30: ...Vantage CNM 2 0 User s Guide 33 Chapter 1 Introducing Vantage ...
Страница 40: ...Vantage CNM 2 0 User s Guide 43 Chapter 2 GUI Introduction ...
Страница 66: ...Vantage CNM 2 0 User s Guide 69 Chapter 4 Configuration Select Device BB General ...
Страница 78: ...Vantage CNM 2 0 User s Guide 81 Chapter 5 Configuration LAN ...
Страница 96: ...Vantage CNM 2 0 User s Guide 99 Chapter 7 Configuration DMZ ...
Страница 126: ...Vantage CNM 2 0 User s Guide 129 Chapter 8 Configuration WAN ...
Страница 140: ...Vantage CNM 2 0 User s Guide 143 Chapter 9 Configuration NAT ...
Страница 144: ...Vantage CNM 2 0 User s Guide 147 Chapter 10 Configuration Static Route ...
Страница 162: ...Vantage CNM 2 0 User s Guide 165 Chapter 11 Configuration VPN ...
Страница 182: ...Vantage CNM 2 0 User s Guide 185 Chapter 12 Configuration Firewall ...
Страница 188: ...Vantage CNM 2 0 User s Guide 191 Chapter 13 Configuration Device Log ...
Страница 236: ...Vantage CNM 2 0 User s Guide 239 Chapter 18 Other System Screens ...
Страница 239: ...Vantage CNM 2 0 User s Guide Chapter 19 Monitor Alarms 242 Figure 132 Monitor Current Alarms ...
Страница 242: ...Vantage CNM 2 0 User s Guide 245 Chapter 19 Monitor Alarms ...
Страница 248: ...Vantage CNM 2 0 User s Guide 251 Chapter 20 Other Monitor Screens ...
Страница 254: ...Vantage CNM 2 0 User s Guide 257 Figure 151 WFTPD Pro Log On ...
Страница 266: ...Vantage CNM 2 0 User s Guide 269 ...
Страница 274: ...Vantage CNM 2 0 User s Guide 277 ...
Страница 286: ...Vantage CNM 2 0 User s Guide 289 ...
Страница 288: ...Vantage CNM 2 0 User s Guide 291 ...
Страница 291: ...Vantage CNM 2 0 User s Guide 294 Figure 181 ESS Provides Campus Wide Coverage ...
Страница 292: ...Vantage CNM 2 0 User s Guide 295 ...
Страница 312: ...Vantage CNM 2 0 User s Guide 315 ...