ZyWALL 50 Internet Security Gateway

Step 3. Enter a descriptive name or comment in the Edit Comments field and press [ENTER].

Step 4. Press [ENTER] at the message [Press ENTER to confirm] to open Menu 21.1.1 - Filter Rules Summary.

Step 5. Enter 1 to configure the first filter rule (the only filter rule of this set). Make the entries in this menu as shown in the following figure.

 

 

 

 

 

 

 

 

Press [SPACE BAR] to choose this filter

 

 

 

 

 

 

 

 

 

 

 

 

 

Menu 21.1.3.1 - TCP/IP Filter Rule

 

 

Filter #: 3,1

 

 

 

 

 

 

rule type. The first filter rule type

 

Filter Type= TCP/IP Filter Rule

 

 

 

 

determines all subsequent filter types

 

Active= Yes

 

 

 

 

 

 

 

 

 

 

 

 

 

within a set.

 

IP Protocol= 6

 

IP Source Route= No

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Destination: IP Addr= 0.0.0.0

 

 

 

 

 

 

 

 

 

IP Mask= 0.0.0.0

 

 

 

 

 

 

 

 

 

 

 

Port #= 23

 

 

 

 

 

 

 

 

 

 

 

Port # Comp= Equal

 

 

 

 

 

 

Select Yes to make the rule active.

 

 

 

Source: IP Addr= 0.0.0.0

 

 

 

 

 

 

 

IP Mask= 0.0.0.0

 

 

 

 

 

 

 

 

 

 

 

Port #= 0

 

 

 

 

 

 

 

 

 

 

 

Port # Comp= None

 

 

 

 

 

 

 

 

 

 

 

TCP Estab= No

 

 

 

 

 

 

6 is the TCP protocol.

 

 

 

 

More= No

 

Log= None

 

 

 

 

 

 

 

Action Matched= Drop

 

 

 

 

 

 

 

 

 

Action Not Matched= Forward

 

 

 

 

 

 

 

 

 

 

 

The port

number for the telnet service (TCP

 

 

Press ENTER to Confirm or ESC to Cancel:

 

 

 

 

Press Space Bar to Toggle.

 

 

protocol)

is 23. See RFC 1060 for port numbers

 

 

 

 

 

 

 

 

 

 

 

 

There are no more rules to

 

 

of well-

known services.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

check.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Select Equal here as you are looking for

 

 

 

 

 

packets going to port 23 only.

Select Drop here so that the packet

will be dropped if its destination is

the telnet port.Select Forward here so that the packet will be forwarded if its destination is not

the telnet port.

Figure 15-12 Example Filter — Menu 21.1.3.1

Filter Configuration

15-15