Chapter 16 ALG
ZyWALL USG 50-H User’s Guide
278
16.3 ALG Technical Reference
Here is more detailed information about the Application Layer Gateway.
ALG
Some applications cannot operate through NAT (are NAT un-friendly) because they embed IP
addresses and port numbers in their packets’ data payload. The ZyWALL examines and uses
IP address and port number information embedded in the VoIP traffic’s data stream. When a
device behind the ZyWALL uses an application for which the ZyWALL has VoIP pass
through enabled, the ZyWALL translates the device’s private IP address inside the data stream
to a public IP address. It also records session port numbers and allows the related sessions to
go through the firewall so the application’s traffic can come in from the WAN to the LAN.
ALG and Trunks
If you send your ALG-managed traffic through an interface trunk and all of the interfaces are
set to active, you can configure routing policies to specify which interface the ALG-managed
traffic uses.
Enable H.323
Transformations
Select this to have the ZyWALL modify IP addresses and port numbers embedded
in the H.323 data payload.
You do not need to use this if you have a H.323 device or server that will modify IP
addresses and port numbers embedded in the H.323 data payload.
H.323 Signaling
Port
If you are using a custom TCP port number (not 1720) for H.323 traffic, enter it here.
Additional H.323
Signaling port
for
transformations
If you are also using H.323 on an additional TCP port number, enter it here.
Enable FTP ALG Turn on the FTP ALG to detect FTP (File Transfer Program) traffic and help build
FTP sessions through the ZyWALL’s NAT. Enabling the FTP ALG also allows you
to use the application patrol to detect FTP traffic and manage the FTP traffic’s
bandwidth (see
Enable FTP
Transformations
Select this option to have the ZyWALL modify IP addresses and port numbers
embedded in the FTP data payload to match the ZyWALL’s NAT environment.
Clear this option if you have an FTP device or server that will modify IP addresses
and port numbers embedded in the FTP data payload to match the ZyWALL’s NAT
environment.
FTP Signaling
Port
If you are using a custom TCP port number (not 21) for FTP traffic, enter it here.
Additional FTP
Signaling port
for
transformations
If you are also using FTP on an additional TCP port number, enter it here.
Apply
Click
Apply
to
save your changes back to the ZyWALL.
Reset
Click
Reset
to begin configuring this screen afresh.
Table 101
Network > ALG (continued)
LABEL
DESCRIPTION
Содержание ZyWall USG 50-H Series
Страница 2: ......
Страница 10: ...Safety Warnings ZyWALL USG 50 H User s Guide 10...
Страница 28: ...Table of Contents ZyWALL USG 50 H User s Guide 28...
Страница 30: ...30...
Страница 34: ...Chapter 1 Introducing the ZyWALL ZyWALL USG 50 H User s Guide 34...
Страница 40: ...Chapter 2 Features and Applications ZyWALL USG 50 H User s Guide 40...
Страница 92: ...Chapter 5 Configuration Basics ZyWALL USG 50 H User s Guide 92...
Страница 130: ...Chapter 6 Tutorials ZyWALL USG 50 H User s Guide 130...
Страница 146: ...146...
Страница 156: ...Chapter 8 Interface ZyWALL USG 50 H User s Guide 156 Figure 128 Network Interface Ethernet Edit wan2...
Страница 157: ...Chapter 8 Interface ZyWALL USG 50 H User s Guide 157 Figure 129 Network Interface Ethernet Edit lan1...
Страница 208: ...Chapter 8 Interface ZyWALL USG 50 H User s Guide 208 Figure 161 Network Interface Bridge Add...
Страница 224: ...Chapter 9 Trunks ZyWALL USG 50 H User s Guide 224...
Страница 250: ...Chapter 12 Zones ZyWALL USG 50 H User s Guide 250...
Страница 280: ...Chapter 16 ALG ZyWALL USG 50 H User s Guide 280...
Страница 286: ...Chapter 17 IP MAC Binding ZyWALL USG 50 H User s Guide 286...
Страница 287: ...287 PART III Firewall Firewall 289...
Страница 288: ...288...
Страница 304: ...Chapter 18 Firewall ZyWALL USG 50 H User s Guide 304...
Страница 306: ...306...
Страница 313: ...Chapter 19 IPSec VPN ZyWALL USG 50 H User s Guide 313 Figure 238 VPN IPSec VPN VPN Connection Edit IKE...
Страница 356: ...Chapter 21 SSL User Screens ZyWALL USG 50 H User s Guide 356...
Страница 358: ...Chapter 22 SSL User Application Screens ZyWALL USG 50 H User s Guide 358...
Страница 368: ...Chapter 24 L2TP VPN ZyWALL USG 50 H User s Guide 368...
Страница 394: ...Chapter 25 L2TP VPN Example ZyWALL USG 50 H User s Guide 394...
Страница 395: ...395 PART V Application Patrol Application Patrol BWM 397...
Страница 396: ...396...
Страница 421: ...421 PART VI Anti X ADP 423...
Страница 422: ...422...
Страница 429: ...Chapter 27 ADP ZyWALL USG 50 H User s Guide 429 Figure 359 Profiles Traffic Anomaly...
Страница 432: ...Chapter 27 ADP ZyWALL USG 50 H User s Guide 432 Figure 360 Profiles Protocol Anomaly...
Страница 440: ...Chapter 27 ADP ZyWALL USG 50 H User s Guide 440...
Страница 442: ...442...
Страница 462: ...Chapter 29 Addresses ZyWALL USG 50 H User s Guide 462...
Страница 474: ...Chapter 31 Schedules ZyWALL USG 50 H User s Guide 474...
Страница 484: ...Chapter 32 AAA Server ZyWALL USG 50 H User s Guide 484...
Страница 506: ...Chapter 34 Certificates ZyWALL USG 50 H User s Guide 506...
Страница 510: ...Chapter 35 SSL Application ZyWALL USG 50 H User s Guide 510...
Страница 511: ...511 PART VIII System System 513...
Страница 512: ...512...
Страница 552: ...552...
Страница 568: ...Chapter 38 Logs ZyWALL USG 50 H User s Guide 568 Figure 464 Maintenance Log Log Setting Edit System Log...
Страница 584: ...Chapter 40 Diagnostics ZyWALL USG 50 H User s Guide 584...
Страница 586: ...Chapter 41 Reboot ZyWALL USG 50 H User s Guide 586...
Страница 596: ...Chapter 43 Product Specifications ZyWALL USG 50 H User s Guide 596...
Страница 598: ...598...
Страница 636: ...Appendix A Log Descriptions ZyWALL USG 50 H User s Guide 636...
Страница 640: ...Appendix B Common Services ZyWALL USG 50 H User s Guide 640...
Страница 646: ...Appendix C Importing Certificates ZyWALL USG 50 H User s Guide 646...