ZyWALL 10 Internet Security Gateway

Chapter 19

Example Firewall Rules

This chapter gives examples for configuring various rules for WAN to LAN and LAN to WAN.

19.1 Examples

Whenever you open a hole in the firewall to forward a service from the Internet to the local network, and NAT is also enabled, you may have to also configure a server behind NAT using SMT menu 15.2. Please see the NAT chapter for more detailed information and also see Figure 14-5for a view of how filtering, the firewall and NAT interact.

19.1.1 Example 1: Firewall Rule To Allow Web Service From The Internet

Let’s say you have one server on the local network, with an IP of 10.100.1.2, supporting FTP, HTTP, Telnet and mail services. The only traffic allowed from the Internet is web service. You want to be able to forward all traffic initiated from the local network. You want to know who accesses your server and send e- mail alerts when this happens. Assume, for example, your mail account is user@zyxel.com. Another network administrator has an e-mail address of user2@zyxel.com. Here are the steps you would follow.

Example Firewall Rules

19-1