![ZyXEL Communications ZyWALL 10/10 Скачать руководство пользователя страница 188](http://html1.mh-extra.com/html/zyxel-communications/zywall-10-10/zywall-10-10_user-manual_944407188.webp)
ZyWALL 10/10 II/50 Internet Security Gateway
18-2
Filter
Configuration
Figure 18-1 Outgoing Packet Filtering Process
For incoming packets, your ZyWALL applies data filters only. Packets are processed depending upon
whether a match is found. The following sections describe how to configure filter sets.
18.1.1 The Filter Structure of the ZyWALL
A filter set consists of one or more filter rules. Usually, you would group related rules, e.g., all the rules for
NetBIOS, into a single set and give it a descriptive name. The ZyWALL allows you to configure up to
twelve filter sets with six rules in each set, for a total of 72 filter rules in the system. You cannot mix device
filter rules and protocol filter rules within the same set. You can apply up to four filter sets to a particular
port to block multiple types of packets. With each filter set having up to six rules, you can have a
maximum of 24 rules active for a single port.
Sets of factory default filter rules have been configured in menu 21 to prevent NetBIOS traffic from
triggering calls and to prevent incoming telnetting. A summary of their filter rules is shown in the figures
that follow.
The following figure illustrates the logic flow when executing a filter rule. See also
for the
logic flow when executing an IP filter.
Data
Outgoing
Packet
Drop
packet
Built-in
default
Call Filters
User-defined
Call Filters
(if applicable)
Initiate call
if line not up
Active Data
Send packet
and reset
Idle Timer
Or
Or
Drop packet
if line not up
Drop packet
if line not up
Send packet
but do not reset
Idle Timer
Send packet
but do not reset
Idle Timer
Match
Match
Match
No
match
No
match
No
match
Call Filtering
Содержание ZyWALL 10/10
Страница 1: ...ZyWALL 10 10 II 50 Internet Security Gateway User s Guide Version 3 50 June 2002...
Страница 32: ......
Страница 36: ......
Страница 42: ......
Страница 54: ...ZyWALL 10 10 II 50 Internet Security Gateway 3 6 Initial Setup Figure 3 5 Advanced Management SMT Menus...
Страница 58: ......
Страница 78: ......
Страница 80: ......
Страница 92: ......
Страница 96: ......
Страница 112: ...ZyWALL 10 10 II 50 Internet Security Gateway 9 16 NAT Figure 9 11 Multiple Servers Behind NAT Example...
Страница 122: ......
Страница 140: ......
Страница 164: ...ZyWALL 10 10 II 50 Internet Security Gateway 13 14 Creating Custom Rules Figure 13 6 Timeout Screen...
Страница 166: ......
Страница 186: ......
Страница 206: ......
Страница 212: ......
Страница 226: ......
Страница 244: ......
Страница 252: ......
Страница 258: ......
Страница 260: ......
Страница 290: ......
Страница 294: ......
Страница 300: ......
Страница 302: ......
Страница 308: ......
Страница 314: ......
Страница 316: ......
Страница 318: ......
Страница 322: ......
Страница 334: ......
Страница 342: ...ZyWALL 10 10 II 50 Internet Security Gateway JJ Index Introduction 10 2...