Page 151 / 944
Scroll up to view Page 146 - 150
Chapter 7 Tutorials
ZyWALL USG 50 User’s Guide
151
1
Click
Configuration > Firewall
>
Add
. Set the
From
field as
WAN
and the
To
field as
DMZ
. Set the
Destination
to the IPPBX’s DMZ IP address object
(
DMZ_SIP
).
IPPBX_DMZ
is the destination because the ZyWALL applies NAT to
traffic before applying the firewall rule. Set the
Access
field to
allow
and click
OK
.
Figure 110
Configuration > Firewall > Add
7.11.5
Set Up a DMZ to LAN Firewall Rule for SIP
The firewall blocks traffic from the DMZ zone to the LAN zone by default so you
need to create a firewall rule to allow the IPPBX to send SIP traffic to the SIP
clients on the LAN.
Page 152 / 944
Chapter 7 Tutorials
ZyWALL USG 50 User’s Guide
152
1
Click
Configuration > Firewall
>
Add
. Set the
From
field as
DMZ
and the
To
field as
LAN
. Set the
Destination
to the IPPBX’s DMZ IP address object
(
DMZ_SIP
).
Set the
Source
to
IPPBX_DMZ
. Leave the
Access
field to
allow
and click
OK
.
Figure 111
Configuration > Firewall > Add
7.12
How to Use Multiple Static Public WAN IP
Addresses for LAN to WAN Traffic
If your ISP gave you a range of static public IP addresses, here is how to configure
a policy route to have the ZyWALL use them for traffic it sends out from the LAN.
7.12.1
Create the Public IP Address Range Object
Click
Configuration > Object > Address > Add
to create the address object
that represents the range of static public IP addresses. In this example you name
it Public-IPs and it goes from 1.1.1.10 to 1.1.1.17.
Figure 112
Creating the Public IP Address Range Object
Page 153 / 944
Chapter 7 Tutorials
ZyWALL USG 50 User’s Guide
153
7.12.2
Configure the Policy Route
Now you need to configure a policy route that has the ZyWALL use the range of
public IP addresses as the source address for WAN to LAN traffic.
Click
Configuration > Network > Routing > Add
.
Although adding a description is optional, it is recommended. This example uses
LAN-to-WAN-Range.
Specifying a
Source Address
is also optional although recommended. This
example uses
LAN_SUBNET1
.
Set the
Source Network Address Translation
to
Public-IPs
and click
OK
.
Figure 113
Configuring the Policy Route
Page 154 / 944
Chapter 7 Tutorials
ZyWALL USG 50 User’s Guide
154