ZyXEL g-2000 plusv2 Guía Del Usuario
ZyXEL G-2000 Plus v2 User’s Guide
Chapter 11 Firewall Screens
145
C
H A P T E R
11
Firewall Screens
This chapter shows you how to configure your ZyXEL device firewall.
11.1 Access Methods
The web configurator is, by far, the most comprehensive firewall configuration tool your
ZyXEL device has to offer. For this reason, it is recommended that you configure your
firewall using the web configurator. SMT screens allow you to activate the firewall. CLI
commands provide limited configuration options and are only recommended for advanced
users, please refer to the Appendix for firewall CLI commands.
ZyXEL device has to offer. For this reason, it is recommended that you configure your
firewall using the web configurator. SMT screens allow you to activate the firewall. CLI
commands provide limited configuration options and are only recommended for advanced
users, please refer to the Appendix for firewall CLI commands.
11.2 Firewall Policies Overview
Firewall rules are grouped based on the direction of travel of packets to which they apply:
Note: The LAN includes both the LAN port and the WLAN.
By default, the ZyXEL device’s stateful packet inspection allows packets traveling in the
following directions:
following directions:
• LAN to LAN/ZyXEL device
This allows computers on the LAN to manage the ZyXEL device and communicate
between networks or subnets connected to the LAN interface.
between networks or subnets connected to the LAN interface.
• LAN to WAN
By default, the ZyXEL device’s stateful packet inspection blocks packets traveling in the
following directions:
following directions:
• WAN to LAN
• WAN to WAN/ZyXEL device
• WAN to WAN/ZyXEL device
This prevents computers on the WAN from using the ZyXEL device as a gateway to
communicate with other computers on the WAN and/or managing the ZyXEL device.
communicate with other computers on the WAN and/or managing the ZyXEL device.
You may define additional rules and sets or modify existing ones but please exercise extreme
caution in doing so.
caution in doing so.
• LAN to LAN/ZyXEL device
• WAN to LAN
• LAN to WAN
• WAN to WAN/ZyXEL device