Chapter 11 Firewall

Packets have a source and a destination. The packet direction matrix in the lower part of the screen sets what the ZyWALL does with packets traveling in a specific direction that do not match any of the firewall rules.

From

 

To

 

A specific interface or any of the ZyWALL’s VPN connections

A specific interface or any of the ZyWALL’s VPN connections

To set the ZyWALL to by default silently block traffic from the WAN from going to the DMZ interfaces, you would find where the From WAN row and the To DMZ column intersect and set the field to Drop as shown.

Figure 125 Default Block Traffic From WAN to DMZ Example

11.3 Packet Direction Examples

Firewall rules are grouped based on the direction of travel of packets to which they apply. This section gives some examples of why you might configure firewall rules for specific connection directions.

 

193

ZyWALL 2 Plus User’s Guide