Chapter 20 Firewall
ZyWALL USG 2000 User’s Guide
311
• The ZyWALL drops most packets from the WAN zone to the ZyWALL itself,
except for VRRP traffic for Device HA and ESP/AH/IKE/NATT/HTTPS services for
VPN tunnels, and generates a log.
• The ZyWALL drops most packets from the DMZ zone to the ZyWALL itself,
except for DNS and NetBIOS traffic, and generates a log.
When you configure a firewall rule for packets destined for the ZyWALL itself,
make sure it does not conflict with your service control rule. See
for more information about service control (remote management). The
ZyWALL checks the firewall rules before the service control rules for traffic
destined for the ZyWALL.
You can configure a To-ZyWALL firewall rule (with From Any To ZyWALL
direction) for traffic from an interface which is not in a zone.
Global Firewall Rules
Firewall rules with from any and/or to any as the packet direction are called
global firewall rules. The global firewall rules are the only firewall rules that apply
to an interface or VPN tunnel that is not included in a zone. The from any rules
apply to traffic coming from the interface and the to any rules apply to traffic
going to the interface.
Firewall Rule Criteria
The ZyWALL checks the schedule, user name (user’s login name on the ZyWALL),
source IP address, destination IP address and IP protocol type of network traffic
against the firewall rules (in the order you list them). When the traffic matches a
rule, the ZyWALL takes the action specified in the rule.
User Specific Firewall Rules
You can specify users or user groups in firewall rules. For example, to allow a
specific user from any computer to access a zone by logging in to the ZyWALL,
you can set up a rule based on the user name only. If you also apply a schedule to
the firewall rule, the user can only access the network at the scheduled time. A
user-aware firewall rule is activated whenever the user logs in to the ZyWALL and
will be disabled after the user logs out of the ZyWALL.
Firewall and Application Patrol
To use a service, make sure both the firewall and application patrol allow the
service’s packets to go through the ZyWALL. The ZyWALL checks the firewall rules
before the application patrol rules for traffic going through the ZyWALL.
Содержание ZyXEL ZyWALL USG-1000
Страница 2: ......
Страница 30: ...30 ...
Страница 58: ...Chapter 3 Web Configurator ZyWALL USG 2000 User s Guide 58 ...
Страница 84: ...Chapter 4 Wizard Setup ZyWALL USG 2000 User s Guide 84 ...
Страница 136: ...Chapter 6 Tutorials ZyWALL USG 2000 User s Guide 136 ...
Страница 165: ...Chapter 9 Signature Update ZyWALL USG 2000 User s Guide 165 Figure 120 Successful System Protect Signature Download ...
Страница 166: ...Chapter 9 Signature Update ZyWALL USG 2000 User s Guide 166 ...
Страница 168: ...168 ...
Страница 234: ...Chapter 11 Trunks ZyWALL USG 2000 User s Guide 234 ...
Страница 248: ...Chapter 12 Policy and Static Routes ZyWALL USG 2000 User s Guide 248 ...
Страница 272: ...Chapter 15 DDNS ZyWALL USG 2000 User s Guide 272 ...
Страница 287: ...Chapter 16 Virtual Servers ZyWALL USG 2000 User s Guide 287 ...
Страница 288: ...Chapter 16 Virtual Servers ZyWALL USG 2000 User s Guide 288 ...
Страница 307: ...307 PART III Firewall Firewall 309 ...
Страница 308: ...308 ...
Страница 326: ...Chapter 20 Firewall ZyWALL USG 2000 User s Guide 326 ...
Страница 328: ...328 ...
Страница 335: ...Chapter 21 IPSec VPN ZyWALL USG 2000 User s Guide 335 Figure 212 VPN IPSec VPN VPN Connection Edit IKE ...
Страница 370: ...Chapter 21 IPSec VPN ZyWALL USG 2000 User s Guide 370 ...
Страница 392: ...Chapter 23 SSL User Screens ZyWALL USG 2000 User s Guide 392 ...
Страница 394: ...Chapter 24 SSL User Application Screens ZyWALL USG 2000 User s Guide 394 ...
Страница 402: ...Chapter 25 SSL User File Sharing ZyWALL USG 2000 User s Guide 402 ...
Страница 412: ...Chapter 27 L2TP VPN ZyWALL USG 2000 User s Guide 412 ...
Страница 440: ...Chapter 28 L2TP VPN Example ZyWALL USG 2000 User s Guide 440 ...
Страница 441: ...441 PART V Application Patrol Application Patrol 443 ...
Страница 442: ...442 ...
Страница 469: ...469 PART VI Anti X Anti Virus 471 IDP 487 ADP 521 Content Filtering 541 Content Filter Reports 567 Anti Spam 575 ...
Страница 470: ...470 ...
Страница 531: ...Chapter 32 ADP ZyWALL USG 2000 User s Guide 531 Figure 371 Profiles Protocol Anomaly ...
Страница 540: ...Chapter 32 ADP ZyWALL USG 2000 User s Guide 540 ...
Страница 566: ...Chapter 33 Content Filtering ZyWALL USG 2000 User s Guide 566 ...
Страница 574: ...Chapter 34 Content Filter Reports ZyWALL USG 2000 User s Guide 574 ...
Страница 593: ...593 PART VII Device HA Device HA 595 ...
Страница 594: ...594 ...
Страница 614: ...614 ...
Страница 636: ...Chapter 38 Addresses ZyWALL USG 2000 User s Guide 636 ...
Страница 660: ...Chapter 41 AAA Server ZyWALL USG 2000 User s Guide 660 ...
Страница 686: ...Chapter 43 Certificates ZyWALL USG 2000 User s Guide 686 ...
Страница 698: ...Chapter 45 SSL Application ZyWALL USG 2000 User s Guide 698 ...
Страница 699: ...699 PART IX System System 701 ...
Страница 700: ...700 ...
Страница 750: ...750 ...
Страница 776: ...Chapter 48 Logs ZyWALL USG 2000 User s Guide 776 ...
Страница 794: ...Chapter 49 Reports ZyWALL USG 2000 User s Guide 794 ...
Страница 796: ...Chapter 50 Diagnostics ZyWALL USG 2000 User s Guide 796 ...
Страница 798: ...Chapter 51 Reboot ZyWALL USG 2000 User s Guide 798 ...
Страница 812: ...Chapter 53 Product Specifications ZyWALL USG 2000 User s Guide 812 ...
Страница 814: ...814 ...
Страница 874: ...Appendix A Log Descriptions ZyWALL USG 2000 User s Guide 874 ...
Страница 956: ...Appendix E Open Software Announcements ZyWALL USG 2000 User s Guide 956 ...
Страница 960: ...Appendix F Legal Information ZyWALL USG 2000 User s Guide 960 ...
Страница 986: ...Index ZyWALL USG 2000 User s Guide 986 ...