Chapter 51 Troubleshooting

Available resource links vary depending on the SSL application object’s configuration.

I cannot download the ZyWALL’s firmware package.

The ZyWALL’s firmware package cannot go through the ZyWALL when you enable the anti-virus Destroy compressed files that could not be decompressed option. The ZyWALL classifies the firmware package as not being able to be decompressed and deletes it.

You can upload the firmware package to the ZyWALL with the option enabled, so you only need to clear the Destroy compressed files that could not be decompressed option while you download the firmware package. See Section

29.2.1on page 469 for more on the anti-virusDestroy compressed files that could not be decompressed option.

I changed the LAN IP address and can no longer access the Internet.

The ZyWALL automatically updates address objects based on an interface’s IP address, subnet, or gateway if the interface’s IP address settings change. However, you need to manually edit any address objects for your LAN that are not based on the interface.

I configured application patrol to allow and manage access to a specific service but access is blocked.

If you want to use a service, make sure both the firewall and application patrol allow the service’s packets to go through the ZyWALL.

The ZyWALL checks firewall rules before it checks application patrol rules for traffic going through the ZyWALL.

I configured application patrol to block use of a specific service but a few packet’s still get through.

The ZyWALL allows the first eight packets to go through the firewall, regardless of the application patrol policy for the application. The ZyWALL examines these first eight packets to identify the application.

 

769

ZyWALL USG 50 User’s Guide