Page 606 / 944 Scroll up to view Page 601 - 605
Chapter 37 Services
ZyWALL USG 50 User’s Guide
606
Both TCP and UDP use ports to identify the source and destination. Each port is a
16-bit number. Some port numbers have been standardized and are used by low-
level system processes; many others have no particular meaning.
Unlike TCP and UDP, Internet Control Message Protocol (ICMP, IP protocol 1) is
mainly used to send error messages or to investigate problems. For example,
ICMP is used to send the response if a computer cannot be reached. Another use
is ping. ICMP does not guarantee delivery, but networks often treat ICMP
messages differently, sometimes looking at the message itself to decide where to
send it.
Service Objects and Service Groups
Use service objects to define IP protocols.
TCP applications
UDP applications
ICMP messages
user-defined services (for other types of IP protocols)
These objects are used in policy routes, firewall rules, and IDP profiles.
Use service groups when you want to create the same rule for several services,
instead of creating separate rules for each service. Service groups may consist of
services and other service groups. The sequence of members in the service group
is not important.
Finding Out More
See
Section 6.6 on page 105
for related information on these screens.
See
Appendix B on page 841
for a list of commonly-used services.
37.2
The Service Summary Screen
The
Service
summary screen provides a summary of all services and their
definitions. In addition, this screen allows you to add, edit, and remove services.
To access this screen, log in to the Web Configurator, and click
Configuration >
Object > Service > Service
. Click a column’s heading cell to sort the table
Page 607 / 944
Chapter 37 Services
ZyWALL USG 50 User’s Guide
607
entries by that column’s criteria. Click the heading cell again to reverse the sort
order.
Figure 347
Configuration > Object > Service > Service
The following table describes the labels in this screen.
Table 183
Configuration > Object > Service > Service
LABEL
DESCRIPTION
Add
Click this to create a new entry.
Edit
Double-click an entry or select it and click
Edit
to be able to modify the
entry’s settings.
Remove
To remove an entry, select it and click
Remove
. The ZyWALL confirms
you want to remove it before doing so.
Object
References
Select an entry and click
Object Reference
s to open a screen that
shows which settings use the entry. See
Section 11.3.2 on page 230
for
an example.
#
This field is a sequential value, and it is not associated with a specific
service.
Name
This field displays the name of each service.
Content
This field displays a description of each service.
Page 608 / 944
Chapter 37 Services
ZyWALL USG 50 User’s Guide
608
37.2.1
The Service Add/Edit Screen
The
Service Add/Edit
screen allows you to create a new service or edit an
existing one. To access this screen, go to the
Service
screen (see
Section 37.2 on
page 606
), and click either the
Add
icon or an
Edit
icon.
Figure 348
Configuration > Object > Service > Service > Edit
The following table describes the labels in this screen.
37.3
The Service Group Summary Screen
The
Service Group
summary screen provides a summary of all service groups. In
addition, this screen allows you to add, edit, and remove service groups.
Table 184
Configuration > Object > Service > Service > Edit
LABEL
DESCRIPTION
Name
Type the name used to refer to the service. You may use 1-31
alphanumeric characters, underscores(
_
), or dashes (-), but the first
character cannot be a number. This value is case-sensitive.
IP Protocol
Select the protocol the service uses. Choices are:
TCP
,
UDP
,
ICMP
, and
User Defined
.
Starting Port
Ending Port
This field appears if the
IP Protocol
is
TCP
or
UDP
. Specify the port
number(s) used by this service. If you fill in one of these fields, the
service uses that port. If you fill in both fields, the service uses the range
of ports.
ICMP Type
This field appears if the
IP Protocol
is
ICMP Type
.
Select the ICMP message used by this service. This field displays the
message text, not the message number.
IP Protocol
Number
This field appears if the
IP Protocol
is
User Defined
.
Enter the number of the next-level protocol (IP protocol). Allowed values
are 0 - 255.
OK
Click
OK
to save your changes back to the ZyWALL.
Cancel
Click
Cancel
to exit this screen without saving your changes.
Page 609 / 944
Chapter 37 Services
ZyWALL USG 50 User’s Guide
609
To access this screen, log in to the Web Configurator, and click
Configuration >
Object
>
Service
>
Service Group
.
Figure 349
Configuration > Object > Service > Service Group
The following table describes the labels in this screen. See
Section 37.3.1 on page
610
for more information as well.
Table 185
Configuration > Object > Service > Service Group
LABEL
DESCRIPTION
Add
Click this to create a new entry.
Edit
Double-click an entry or select it and click
Edit
to be able to modify the
entry’s settings.
Remove
To remove an entry, select it and click
Remove
. The ZyWALL confirms
you want to remove it before doing so.
Object
References
Select an entry and click
Object Reference
s to open a screen that
shows which settings use the entry. See
Section 11.3.2 on page 230
for
an example.
#
This field is a sequential value, and it is not associated with a specific
service group.
Name
This field displays the name of each service group.
By default, the ZyWALL uses services starting with “Default_Allow_” in
the firewall rules to allow certain services to connect to the ZyWALL.
Description
This field displays the description of each service group, if any.
Page 610 / 944
Chapter 37 Services
ZyWALL USG 50 User’s Guide
610
37.3.1
The Service Group Add/Edit Screen
The
Service Group Add/Edit
screen allows you to create a new service group or
edit an existing one. To access this screen, go to the
Service Group
screen (see
Section 37.3 on page 608
), and click either the
Add
icon or an
Edit
icon.
Figure 350
Configuration > Object > Service > Service Group > Edit
The following table describes the labels in this screen.
Table 186
Configuration > Object > Service > Service Group > Edit
LABEL
DESCRIPTION
Name
Enter the name of the service group. You may use 1-31 alphanumeric
characters, underscores(
_
), or dashes (-), but the first character cannot
be a number. This value is case-sensitive.
Description
Enter a description of the service group, if any. You can use up to 60
printable ASCII characters.
Member List
The
Member
list displays the names of the service and service group
objects that have been added to the service group. The order of
members is not important.
Select items from the
Available
list that you want to be members and
move them to the
Member
list. You can double-click a single entry to
move it or use the [Shift] or [Ctrl] key to select multiple entries and use
the arrow button to move them.
Move any members you do not want included to the
Available
list.
OK
Click
OK
to save your changes back to the ZyWALL.
Cancel
Click
Cancel
to exit this screen without saving your changes.

Rate

4.5 / 5 based on 2 votes.

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top