Chapter 22 Firewall

The ordering of your rules is very important as rules are applied in sequence.

Figure 223 Configuration > Firewall

The following table describes the labels in this screen.

Table 107 Configuration > Firewall

LABEL

DESCRIPTION

General

 

Settings

 

 

 

Enable

Select this check box to activate the firewall. The ZyWALL performs

Firewall

access control when the firewall is activated.

 

 

Allow

If an alternate gateway on the LAN has an IP address in the same subnet

Asymmetrical

as the ZyWALL’s LAN IP address, return traffic may not go through the

Route

ZyWALL. This is called an asymmetrical or “triangle” route. This causes

 

the ZyWALL to reset the connection, as the connection has not been

 

acknowledged.

 

Select this check box to have the ZyWALL permit the use of asymmetrical

 

route topology on the network (not reset the connection).

Note: Allowing asymmetrical routes may let traffic from the WAN go directly to the LAN without passing through the ZyWALL. A better solution is to use virtual interfaces to put the ZyWALL and the backup gateway on separate subnets.

Firewall Rule Summary

 

367

ZyWALL USG 50 User’s Guide