Chapter 11 Firewall

"The ordering of your rules is very important as rules are applied in the order that they are listed.

See Section 11.1 on page 191 for more information about the firewall.

When the ZyWALL is in bridge mode, enable the default WAN to LAN firewall rule for the BOOTP_CLIENT service to let DHCP clients behind the ZyWALL use a DHCP server on the WAN.

Enable the default WAN to LAN firewall rule for the NetBIOS service to let computers behind the ZyWALL access devices on the WAN using computer names.

Figure 137 SECURITY > FIREWALL > Rule Summary

The following table describes the labels in this screen.

Table 50 SECURITY > FIREWALL > Rule Summary

LABEL

DESCRIPTION

Packet Direction

Use the drop-down list boxes and click Refresh to select a direction of travel of

 

packets for which you want to display firewall rules.

 

Note: The VPN connection directions apply to the traffic going to or

 

from the ZyWALL’s VPN tunnels. They do not apply to other

 

VPN traffic for which the ZyWALL is not one of the gateways

 

(VPN pass-through traffic).

 

 

+/-

In the heading row, click + to expand or - to collapse the Source Address,

 

Destination Address and Service Type drop down lists for all of the displayed

 

rules.

 

 

Default Policy

This field displays the default action you selected in the Default Rule screen for the

 

packet direction displayed.

 

207

ZyWALL 2 Plus User’s Guide