ZyXEL Communications P-870HW-I User Manual

Page of 438
P-870HW-I1 User’s Guide
Chapter 11 Firewalls
155
The following table describes the labels in this screen. 
11.5  Firewall Rules Screen
Note: The ordering of your rules is very important as rules are applied in turn.
Use this screen to activate the firewall and to set the default rules for each direction. To open 
this screen, click Security > Firewall > Rules.
Table 64   Security > Firewall > General
LABEL
DESCRIPTION
Active Firewall
Select this check box to activate the firewall. The ZyXEL Device performs access 
control and protects against Denial of Service (DoS) attacks when the firewall is 
activated.
Bypass Triangle 
Route
Select this check box to have the ZyXEL Device firewall permit the use of triangle 
route topology on the network. See the appendix for more on triangle route 
topology.
Note: Allowing asymmetrical routes may let traffic from the WAN go 
directly to a LAN computer without passing through the 
router.
Packet Direction
This is the direction of travel of packets (LAN to LAN / RouterLAN to WAN
WAN to WAN / RouterWAN to LAN).
Firewall rules are grouped based on the direction of travel of packets to which they 
apply. For example, LAN to LAN / Router means packets traveling from a 
computer/subnet on the LAN to either another computer/subnet on the LAN 
interface of the ZyXEL Device or the ZyXEL Device itself. 
Default Action
Use the drop-down list boxes to select the default action that the firewall is take on 
packets that are traveling in the selected direction and do not match any of the 
firewall rules. 
Select Drop to silently discard the packets without sending a TCP reset packet or 
an ICMP destination-unreachable message to the sender.
Select Reject to deny the packets and send a TCP reset packet (for a TCP packet) 
or an ICMP destination-unreachable message (for a UDP packet) to the sender.
Select Permit to allow the passage of the packets. 
Log
Select the check box to create a log (when the above action is taken) for packets 
that are traveling in the selected direction and do not match any of your customized 
rules.
Expand...
Click this button to display more information.
Basic...
Click this button to display less information.
Apply
Click this to save your changes back to the ZyXEL Device.
Cancel
Click this to begin configuring this screen afresh.