ZyWALL 10/50 Internet Security Gateway

Step 4. Enter a descriptive name or comment in the Edit Comments field and press [ENTER].

Step 5. Press [ENTER] at the message [Press ENTER to confirm] to open Menu 21.1.3 - Filter Rules Summary.

Step 6. Enter 1 to configure the first filter rule (the only filter rule of this set). Make the entries in this menu as shown in the following figure.

 

 

 

 

 

 

 

 

 

Press [SPACE BAR] to choose this filter rule

 

 

 

 

 

 

 

 

 

 

 

 

 

Menu 21.1.3.1 - TCP/IP Filter Rule

 

 

 

 

 

 

type. The first filter rule type determines all

 

Filter #: 3,1

 

 

 

 

 

 

 

Filter Type= TCP/IP Filter Rule

 

 

 

 

subsequent filter types within a set.

 

Active= Yes

 

IP Source Route= No

 

 

 

 

 

 

 

 

 

IP Protocol= 6

 

 

 

 

 

 

 

 

 

 

Destination: IP Addr= 0.0.0.0

 

 

 

 

 

 

 

 

 

IP Mask= 0.0.0.0

 

 

 

 

 

 

 

 

 

 

 

Port #= 23

 

 

 

 

 

 

 

 

 

 

 

Port # Comp= Equal

 

 

 

 

 

 

Select Yes to make the rule active.

 

 

 

Source: IP Addr= 0.0.0.0

 

 

 

 

 

 

 

IP Mask= 0.0.0.0

 

 

 

 

 

 

 

 

 

 

 

Port #= 0

 

 

 

 

 

 

 

 

 

 

 

Port # Comp= None

 

 

 

 

 

 

 

 

 

 

 

TCP Estab= No

 

Log= None

 

 

 

 

 

 

 

 

 

More= No

 

 

 

 

 

6 is the TCP protocol.

 

 

 

Action Matched= Drop

 

 

 

 

 

 

 

 

 

Action Not Matched= Forward

 

 

 

 

 

 

 

 

 

Press ENTER to Confirm or ESC to Cancel:

 

 

The port

 

number for the telnet service (TCP protocol)

 

 

 

 

 

 

 

 

 

 

 

Press Space Bar to Toggle.

 

 

is 23. See

RFC 1060 for port numbers of well-known

 

 

 

 

There are no more rules to check.

 

services.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Select Equal here as you are looking for packets

 

 

 

 

 

going to port 23 only.

Select Drop here so that the packet will

be dropped if its destination is the telnet

port.

Select Forward here so that the packet will be

forwarded if its destination is not the telnet port.

Figure 18-11 Example Filter — Menu 21.1.3.1

Filter Configuration

18-15