Chapter 5 Configuration Basics

The ZyWALL does not check to-ZyWALL firewall rules for packets that are redirected by virtual server. It does check regular (through-ZyWALL) firewall rules.

MENU ITEM(S)

Network > Virtual Server

PREREQUISITES

Interfaces, addresses (HOST)

 

 

Example: Suppose you have an FTP server with a private IP address connected to a DMZ port. You could configure a virtual server rule to forwards FTP sessions from the WAN to the DMZ.

1Click Network > Virtual Server to configure the virtual server. Add an entry.

2Name the entry.

3Select the WAN interface that the FTP traffic is to come in through (in this example, wan1 or wan2.)

4Specify the public WAN IP address where the ZyWALL will receive the FTP packets.

5In the Mapped IP field, list the IP address of the FTP server. The ZyWALL will forward the packets received for the original IP address.

6In Mapping Type, select Port.

7Enter 21 in both the Original and the Mapped Port fields.

5.4.20HTTP Redirect

Configure this feature to have the ZyWALL transparently forward HTTP (web) traffic to a proxy server. This can speed up web browsing because the proxy server keeps copies of the web pages that have been accessed so they are readily available the next time one of your users needs to access that page.

The ZyWALL does not check to-ZyWALL firewall rules for packets that are redirected by HTTP redirect. It does check regular (through-ZyWALL) firewall rules.

MENU ITEM(S)

Network > HTTP Redirect

PREREQUISITES

Interfaces

 

 

Example: Suppose you want HTTP requests from your LAN1 to go to a HTTP proxy server at IP address 192.168.3.80.

1Click Network > HTTP Redirect.

2Add an entry.

3Name the entry.

4Select the interface from which you want to redirect incoming HTTP requests (lan1).

5Specify the IP address of the HTTP proxy server.

6Specify the port number to use for the HTTP traffic that you forward to the proxy server.

5.4.21ALG

The ZyWALL’s Application Layer Gateway (ALG) allows VoIP and FTP applications to go through NAT on the ZyWALL. You can also specify additional signaling port numbers.

MENU ITEM(S)

Network > ALG

 

 

120

 

ZyWALL USG 100/200 Series User’s Guide