ZyWALL 2 and ZyWALL 2WE

 

Table 16-1 Firewall Rules Summary: First Screen

 

 

FIELD

DESCRIPTION

 

 

Bypass Triangle

Select this check box to have the ZyWALL firewall ignore the use of triangle route

Route

topology on the network. See the appendices for more on triangle route topology.

 

 

Total Configured

This read-only number is the total number of rules that have been configured for the

Rules

ZyWALL (the combined total for all packet directions). The ZyWALL allows you to

 

configure up to 30 firewall rules total.

 

 

Vacant Rules

This read-only number is the number of rules that can still be configured for the

 

ZyWALL (the combined total available for all packet directions).

Packet Direction

Use the drop-down list box to select a direction of travel of packets (LAN to

 

LAN/ZyWALL, LAN to WAN, WAN to WAN/ZyWALL, WAN to LAN) for which you

 

want to configure firewall rules.

Block

Use the option buttons to select whether to Block (discard) or Forward (allow the

Forward

passage of) packets that are traveling in the selected direction.

 

 

Log

Select the check box to create a log (when the above action is taken) for packets

 

that are traveling in the selected direction and do not match any of the rules below.

 

 

The following read-only fields summarize the rules you have created that apply to traffic traveling in the selected packet direction. The firewall rules that you configure (summarized below) take priority over the general firewall action settings above.

Index

This is your firewall rule number. The ordering of your rules is important as rules are

 

applied in turn. The Move field below allows you to reorder your rules.

 

 

Status

This field displays whether a firewall is turned on (Active) or not (Inactive). Rules

 

that have not been configured display Empty.

Source Address

This drop-down list box displays the source addresses or ranges of addresses to

 

which this firewall rule applies. Please note that a blank source or destination

 

address is equivalent to Any.

Destination

This drop-down list box displays the destination addresses or ranges of addresses to

Address

which this firewall rule applies. Please note that a blank source or destination

 

address is equivalent to Any.

Service Type

This drop-down list box displays the services to which this firewall rule applies.

 

Please note that a blank service type is equivalent to Any. See Table 16-2for more

 

information.

 

 

Action

This is the specified action for that rule, either Block or Forward. Note that Block

 

means the firewall silently discards the packet.

 

 

16-6

Creating Custom Rules