ZyWALL 10 Internet Security Gateway

The following table describes how to configure your TCP/IP filter rule.

Table 7-3 TCP/IP Filter Rule Menu Fields

FIELD

DESCRIPTION

OPTIONS

Active

Yes activates the filter rule and No deactivates it.

Yes/No

 

 

 

IP Protocol

Protocol refers to the upper layer protocol, e.g., TCP is 6,

0-255

 

UDP is 17 and ICMP is 1. This value must be between 0

 

 

and 255. A value of 0 matches ANY protocol.

 

IP Source Route

If Yes, the rule applies to packet with IP source route

Yes/No

 

option; else the packet must not have source route option.

 

 

The majority of IP packets do not have source route.

 

 

 

 

Destination

 

 

 

 

 

IP Address

Enter the destination IP Address of the packet you wish to

0.0.0.0

 

filter. This field is ignored if it is 0.0.0.0.

 

IP Mask

Enter the IP mask to apply to the Destination: IP Addr.

0.0.0.0

 

 

 

Port #

Enter the destination port of the packets that you wish to

0-65535

 

filter. The range of this field is 0 to 65535. This field is

 

 

ignored if it is 0.

 

 

 

 

Port # Comp

Select the comparison to apply to the destination port in

None/Less/Greater/

 

the packet against the value given in Destination: Port #.

Equal/Not Equal]

Source

 

 

 

 

 

IP Address

Enter the source IP Address of the packet you wish to

0.0.0.0

 

filter. This field is ignored if it is 0.0.0.0.

 

 

 

 

IP Mask

Enter the IP mask to apply to the Source: IP Addr.

0.0.0.0

 

 

 

Port #

Enter the source port of the packets that you wish to filter.

0-65535

 

The range of this field is 0 to 65535. This field is ignored if

 

 

it is 0.

 

Port # Comp

Select the comparison to apply to the source port in the

None/Less/Greater/

 

packet against the value given in Source: Port #.

Equal/Not Equal

TCP Estab

This field is applicable only when the IP Protocol field is 6,

Yes/No

 

TCP. If Yes, the rule matches packets that want to

 

 

establish a TCP connection (SYN=1 and ACK=0); if No, it

 

 

is ignored.

 

More

If Yes, a matching packet is passed to the next filter rule

Yes/No

 

before an action is taken; if No, the packet is disposed of

 

7-8

Filters