ZyWALL 10/50 Internet Security Gateway

Table 18-3 TCP/IP Filter Rule Menu Fields

FIELD

DESCRIPTION

OPTIONS

 

 

 

Port # Comp

Select the comparison to apply to the destination port in the packet

None

 

against the value given in Destination: Port #.

Less

 

 

Greater

 

 

Equal

 

 

Not Equal

Source

 

 

 

 

 

IP Address

Enter the source IP Address of the packet you wish to filter. This

0.0.0.0

 

field is ignored if it is 0.0.0.0.

 

 

 

 

IP Mask

Enter the IP mask to apply to the Source: IP Addr.

0.0.0.0

 

 

 

Port #

Enter the source port of the packets that you wish to filter. The

0-65535

 

range of this field is 0 to 65535. This field is ignored if it is 0.

 

 

 

 

Port # Comp

Select the comparison to apply to the source port in the packet

None

 

against the value given in Source: Port #.

Less

 

 

Greater

 

 

Equal

 

 

Not Equal

TCP Estab

This field is applicable only when the IP Protocol field is 6, TCP. If

Yes

 

Yes, the rule matches packets that want to establish a TCP

No

 

connection (SYN=1 and ACK=0); if No, it is ignored.

 

More

If Yes, a matching packet is passed to the next filter rule before an

Yes

 

action is taken; if No, the packet is disposed of according to the

No

 

action fields.

 

 

If More is Yes, then Action Matched and Action Not Matched will

 

 

be N/A.

 

Log

Select the logging option from the following:

 

 

None – No packets will be logged.

None

 

Action Matched - Only packets that match the rule parameters will

Action Matched

 

be logged.

Action Not

 

 

 

Action Not Matched - Only packets that do not match the rule

Matched

 

parameters will be logged.

Both

 

Both – All packets will be logged.

 

 

 

 

 

Action

Select the action for a matching packet.

Check Next Rule

Matched

 

Forward

 

 

 

 

 

Filter Configuration

18-9