
ZyWALL 50 Internet Security Gateway
Step 3. Enter a descriptive name or comment in the Edit Comments field and press [ENTER].
Step 4. Press [ENTER] at the message [Press ENTER to confirm] to open Menu 21.1.1 - Filter Rules Summary.
Step 5. Enter 1 to configure the first filter rule (the only filter rule of this set). Make the entries in this menu as shown in the following figure.
|
|
|
|
|
|
|
| Press [SPACE BAR] to choose this filter | ||||
|
|
|
|
|
|
|
|
| ||||
|
|
|
| Menu 21.1.3.1 - TCP/IP Filter Rule |
| |||||||
| Filter #: 3,1 |
|
|
|
|
|
| rule type. The first filter rule type | ||||
| Filter Type= TCP/IP Filter Rule |
|
|
|
| determines all subsequent filter types | ||||||
| Active= Yes |
|
|
|
|
|
| |||||
|
|
|
|
|
|
| within a set. | |||||
| IP Protocol= 6 |
| IP Source Route= No |
|
|
|
| |||||
|
|
|
|
|
|
|
|
|
| |||
| Destination: IP Addr= 0.0.0.0 |
|
|
|
|
|
|
|
| |||
| IP Mask= 0.0.0.0 |
|
|
|
|
|
|
|
|
|
| |
| Port #= 23 |
|
|
|
|
|
|
|
|
|
| |
| Port # Comp= Equal |
|
|
|
|
|
| Select Yes to make the rule active. |
|
| ||
| Source: IP Addr= 0.0.0.0 |
|
|
|
|
|
| |||||
| IP Mask= 0.0.0.0 |
|
|
|
|
|
|
|
|
|
| |
| Port #= 0 |
|
|
|
|
|
|
|
|
|
| |
| Port # Comp= None |
|
|
|
|
|
|
|
|
|
| |
| TCP Estab= No |
|
|
|
|
|
| 6 is the TCP protocol. |
|
|
| |
| More= No |
| Log= None |
|
|
|
|
|
| |||
| Action Matched= Drop |
|
|
|
|
|
|
|
| |||
| Action Not Matched= Forward |
|
|
|
|
|
|
|
| |||
|
|
| The port | number for the telnet service (TCP |
| |||||||
| Press ENTER to Confirm or ESC to Cancel: |
|
|
| ||||||||
| Press Space Bar to Toggle. |
|
| protocol) | is 23. See RFC 1060 for port numbers |
| ||||||
|
|
|
|
|
|
|
| |||||
|
|
| There are no more rules to |
|
| of well- | known services. |
| ||||
|
|
|
|
| ||||||||
|
|
|
|
|
|
|
|
|
|
| ||
|
|
| check. |
|
|
|
|
|
|
|
| |
|
|
|
|
|
|
|
|
|
|
| ||
|
|
|
|
|
|
|
| |||||
|
|
|
|
| Select Equal here as you are looking for | |||||||
|
|
|
|
| packets going to port 23 only. |
Select Drop here so that the packet
will be dropped if its destination is
the telnet port.Select Forward here so that the packet will be forwarded if its destination is not
the telnet port.
FigureFilter Configuration |