Page 201 / 427 Scroll up to view Page 196 - 200
P-2602H(W)(L)-DxA Series User’s Guide
Chapter 14 Firewall Configuration
201
The following table describes the labels in this screen.
Table 72
Firewall: Edit Rule
LABEL
DESCRIPTION
Active
Select this option to enable this firewall rule.
Action for Matched
Packet
Use the drop-down list box to select whether to discard (
Drop
), deny
and send
an ICMP destination-unreachable message to the sender of (
Reject
) or allow the
passage of (
Permit
) packets that match this rule.
Source/Destination
Address
Address Type
Do you want your rule to apply to packets with a particular (single) IP, a range of
IP addresses (e.g., 192.168.1.10 to 192.169.1.50), a subnet or any IP address?
Select an option from the drop-down list box that includes:
Single Address
,
Range Address
,
Subnet Address
and
Any
Address
.
Start IP Address
Enter the single IP address or the starting IP address in a range here.
End IP Address
Enter the ending IP address in a range here.
Subnet Mask
Enter the subnet mask here, if applicable.
Add >>
Click
Add >>
to add a new address to the
Source
or
Destination Address
box.
You can add multiple addresses, ranges of addresses, and/or subnets.
Edit <<
To edit an existing source or destination address, select it from the box and click
Edit <<
.
Delete
Highlight an existing source or destination address from the
Source
or
Destination Address
box above and click
Delete
to remove it.
Services
Available/ Selected
Services
Please see
Appendix F on page 371
for more information on services available.
Highlight a service from the
Available Services
box on the left, then click
Add
>>
to add it to the
Selected Services
box on the right. To remove a service,
highlight it in the
Selected Services
box on the right, then click
Remove
.
Edit Customized
Service
Click the
Edit Customized Services
link to bring up the screen that you use to
configure a new custom service that is not in the predefined list of services.
Schedule
Day to Apply
Select everyday or the day(s) of the week to apply the rule.
Time of Day to
Apply (24-Hour
Format)
Select
All Day
or enter the start and end times in the hour-minute format to apply
the rule.
Log
Log Packet Detail
Information
This field determines if a log for packets that match the rule is created or not. Go
to the
Log Settings
page and select the
Access Control
logs category to have
the ZyXEL Device record these logs.
Alert
Send Alert Message
to Administrator
When Matched
Select the check box to have the ZyXEL Device generate an alert when the rule
is matched.
Back
Click
Back
to return to the previous screen.
Apply
Click
Apply
to save your customized settings and exit this screen.
Cancel
Click
Cancel
to exit this screen without saving.
Page 202 / 427
P-2602H(W)(L)-DxA Series User’s Guide
202
Chapter 14 Firewall Configuration
14.6.2
Customized Services
Configure customized services and port numbers not predefined by the ZyXEL Device. For a
comprehensive list of port numbers and services, visit the IANA (Internet Assigned Number
Authority) website. See
Appendix F on page 371
for some examples. Click the
Edit
Customized Services
link while editing a firewall rule to configure a custom service port.
This displays the following screen.
Refer to
Section 13.1 on page 181
for more information.
Figure 106
Firewall: Customized Services
The following table describes the labels in this screen.
14.6.3
Configuring A Customized Service
Click a rule number in the
Firewall Customized Services
screen to create a new custom port
or edit an existing one. This action displays the following screen.
Refer to
Section 13.1 on page 181
for more information.
Table 73
Customized Services
LABEL
DESCRIPTION
No.
This is the number of your customized port. Click a rule’s number of a service to go to the
Firewall Customized Services Config
screen to configure or edit a customized service.
Name
This is the name of your customized service.
Protocol
This shows the IP protocol (
TCP
,
UDP
or
TCP/UDP
) that defines your customized
service.
Port
This is the port number or range that defines your customized service.
Back
Click
Back
to return the
Firewall Edit Rule
screen.
Page 203 / 427
P-2602H(W)(L)-DxA Series User’s Guide
Chapter 14 Firewall Configuration
203
Figure 107
Firewall: Configure Customized Services
The following table describes the labels in this screen.
14.7
Example Firewall Rule
The following Internet firewall rule example allows a hypothetical “MyService” connection
from the Internet.
1
Click
Security > Firewall
>
Rules
.
2
Select
WAN to LAN
in the
Packet Direction
field.
Table 74
Firewall: Configure Customized Services
LABEL
DESCRIPTION
Service Name
Type a unique name for your custom port.
Service Type
Choose the IP port (
TCP
,
UDP
or
TCP/UDP
) that defines your customized port from
the drop down list box.
Port Configuration
Type
Click
Single
to specify one port only or
Range
to specify a span of ports that define
your customized service.
Port Number
Type a single port number or the range of port numbers that define your customized
service.
Apply
Click
Apply
to save your customized settings and exit this screen.
Cancel
Click
Cancel
to return to the previously saved settings.
Delete
Click
Delete
to delete the current rule.
Page 204 / 427
P-2602H(W)(L)-DxA Series User’s Guide
204
Chapter 14 Firewall Configuration
Figure 108
Firewall Example: Rules
3
In the
Rules
screen, select the index number after that you want to add the rule. For
example, if you select “6”, your new rule becomes number 7 and the previous rule 7 (if
there is one) becomes rule 8.
4
Click
Add
to display the firewall rule configuration screen.
5
In the
Edit Rule
screen, click the
Edit
Customized Services
link to open the
Customized Service
screen.
6
Click an index number to display the
Customized Services Config
screen and configure
the screen as follows and click
Apply
.
Figure 109
Edit Custom Port Example
7
Select
Any
in the
Destination Address
box and then click
Delete
.
8
Configure the destination address screen as follows and click
Add
.
Page 205 / 427
P-2602H(W)(L)-DxA Series User’s Guide
Chapter 14 Firewall Configuration
205
Figure 110
Firewall Example: Edit Rule: Destination Address
9
Use the
Add >>
and
Remove
buttons between
Available Services
and
Selected Services
list boxes to configure it as follows. Click
Apply
when you are done.
Note:
Custom services show up with an “*” before their names in the
Services
list
box and the
Rules
list box.

Rate

3.5 / 5 based on 2 votes.

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top