Chapter 14 Firewall
Blocked
14.1.4.2
How can you forward certain WAN to LAN traffic? You may allow traffic originating from the WAN to be forwarded to the LAN by:
•Configuring NAT port forwarding rules.
•Configuring WAN or LAN & WAN access for services in the Remote Management screens. When you allow remote management from the WAN, you are actually configuring
Forwarded
14.2 Triangle Route
When the firewall is on, your ZyXEL Device acts as a secure gateway between your LAN and the Internet. In an ideal network topology, all incoming and outgoing network traffic passes through the ZyXEL Device to protect your LAN against attacks.
Figure 104 Ideal Firewall Setup
14.2.1 The “Triangle Route” Problem
A traffic route is a path for sending or receiving data packets between two Ethernet devices. You may have more than one connection to the Internet (through one or more ISPs). If an alternate gateway is on the LAN (and its IP address is in the same subnet as the ZyXEL Device’s LAN IP address), the “triangle route” (also called asymmetrical route) problem may occur. The steps below describe the “triangle route” problem.
1A computer on the LAN initiates a connection by sending out a SYN packet to a receiving server on the WAN.
| 181 |
|
|