ZyWALL 10/50 Internet Security Gateway
|
|
|
|
|
|
|
|
|
|
| Call Filtering |
|
|
|
|
|
|
|
|
|
|
|
|
|
| |||
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| ||
|
|
|
|
| No |
| No |
| No |
| Active Data |
| ||||||||||||||||
|
|
|
|
|
|
|
|
|
|
|
|
|
| |||||||||||||||
Outgoing |
|
| Data | match | default | match | Call Filters |
| match |
|
| Initiate call |
| |||||||||||||||
Packet |
|
|
|
| Call Filters |
|
|
|
| (if applicable) |
|
|
|
| if line not up |
| ||||||||||||
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| Send packet | ||
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |||
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| ||||||
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| and reset | |
|
|
|
| Match |
| Match |
|
|
|
|
| Match |
|
|
|
|
|
| Idle Timer | |||||||||
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| ||||||||||
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| Drop |
|
| Drop packet |
|
|
|
|
| Drop packet |
|
|
|
|
|
|
|
|
|
| ||||||
|
|
| packet |
|
| if line not up |
|
|
|
|
| if line not up |
|
|
|
|
|
|
|
|
|
| ||||||
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| Or |
|
|
|
|
|
| Or |
|
|
|
|
|
|
|
|
| |||
|
|
|
|
|
|
|
|
|
|
|
| Send packet |
|
|
|
|
| Send packet |
|
|
|
|
|
| ||||
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |||||||||||
|
|
|
|
|
|
|
|
|
|
| but do not reset |
|
| but do not reset |
| |||||||||||||
|
|
|
|
|
|
|
|
|
|
|
| Idle Timer |
|
|
|
|
|
| Idle Timer |
|
|
|
|
|
| |||
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
For incoming packets, your ZyWALL applies data filters only. Packets are processed depending upon whether a match is found. The following sections describe how to configure filter sets.
18.1.1 The Filter Structure of the ZyWALL
A filter set consists of one or more filter rules. Usually, you would group related rules, e.g., all the rules for NetBIOS, into a single set and give it a descriptive name. The ZyWALL allows you to configure up to twelve filter sets with six rules in each set, for a total of 72 filter rules in the system. You cannot mix device filter rules and protocol filter rules within the same set. You can apply up to four filter sets to a particular port to block multiple types of packets. With each filter set having up to six rules, you can have a maximum of 24 rules active for a single port.
Sets of factory default filter rules have been configured in menu 21 to prevent NetBIOS traffic from triggering calls and to prevent incoming telnetting. A summary of their filter rules is shown in the figures that follow.
The following figure illustrates the logic flow when executing a filter rule. See also Figure
Filter Configuration |