ZyAIR G-2000 Plus User’s Guide

CH A P T E R 15

Firewall Screens

This chapter shows you how to configure your ZyAIR firewall.

15.1 Access Methods

The web configurator is, by far, the most comprehensive firewall configuration tool your ZyAIR has to offer. For this reason, it is recoZyAIRmmended that you configure your firewall using the web configurator. SMT screens allow you to activate the firewall. CLI commands provide limited configuration options and are only recommended for advanced users, please refer to the Appendix for firewall CLI commands.

15.2 Firewall Policies Overview

Firewall rules are grouped based on the direction of travel of packets to which they apply:

LAN to LAN/ZyAIR

WAN to LAN

LAN to WAN

WAN to WAN/ZyAIR

Note: The LAN includes both the LAN port and the WLAN.

By default, the ZyAIR’s stateful packet inspection allows packets traveling in the following directions:

LAN to LAN/ZyAIR

This allows computers on the LAN to manage the ZyAIR and communicate between networks or subnets connected to the LAN interface.

LAN to WAN

By default, the ZyAIR’s stateful packet inspection blocks packets traveling in the following directions:

WAN to LAN

WAN to WAN/ZyAIR

This prevents computers on the WAN from using the ZyAIR as a gateway to communicate with other computers on the WAN and/or managing the ZyAIR.

Chapter 15 Firewall Screens

192