Chapter 6 Configuration Basics

The DMZ zone contains the dmz interface (physical port P6). The DMZ zone has servers that are available to the public. The dmz interface uses private IP address 192.168.3.1 and the connected devices use private IP addresses in the 192.168.3.2 to 192.168.3.254 range.

6.3Terminology in the ZyWALL

This section highlights some terminology or organization for ZLD-based ZyWALLs.

Table 15 ZLD ZyWALL Terminology

FEATURE / TERM

ZLD ZYWALL FEATURE / TERM

IP alias

Virtual interface

 

 

Gateway policy

VPN gateway

 

 

Network policy (IPSec SA)

VPN connection

 

 

Source NAT (SNAT)

Policy route

 

 

Trigger port, port triggering

Policy route

 

 

Address mapping

Policy route

 

 

Address mapping (VPN)

IPSec VPN

 

 

Interface bandwidth management

Interface

(outbound)

 

 

 

General bandwidth management

Policy route

 

 

6.4 Packet Flow

Here is the order in which the ZyWALL applies its features and checks.

 

91

ZyWALL USG 20/20W User’s Guide