ZyXEL LTE7485-S905 User Guide - Page 127

Firewall Technical Reference, 11.7.1 Firewall Rules Overview

Page 127 highlights

Chapter 11 Firewall The following table describes the labels in this screen. Table 47 Security > Firewall > DoS LABEL DESCRIPTION DoS Protection Blocking Enable this to protect against DoS attacks. The Zyxel Device will drop sessions that surpass maximum thresholds. Apply Click this to save your changes. Cancel Click this to restore your previously saved settings. 11.7 Firewall Technical Reference This section provides some technical background information about the topics covered in this chapter. 11.7.1 Firewall Rules Overview Your customized rules take precedence and override the Zyxel Device's default settings. The Zyxel Device checks the source IP address, destination IP address and IP protocol type of network traffic against the firewall rules (in the order you list them). When the traffic matches a rule, the Zyxel Device takes the action specified in the rule. Firewall rules are grouped based on the direction of travel of packets to which they apply: • LAN to Router • LAN to WAN • WAN to LAN • WAN to Router By default, the Zyxel Device's stateful packet inspection allows packets traveling in the following directions: • LAN to Router These rules specify which computers on the LAN can manage the Zyxel Device (remote management). Note: You can also configure the remote management settings to allow only a specific computer to manage the Zyxel Device. • LAN to WAN These rules specify which computers on the LAN can access which computers or services on the WAN. By default, the Zyxel Device's stateful packet inspection drops packets traveling in the following directions: • WAN to LAN These rules specify which computers on the WAN can access which computers or services on the LAN. Note: You also need to configure NAT port forwarding (or full featured NAT address mapping rules) to allow computers on the WAN to access devices on the LAN. LTE Series User's Guide 127

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210

Chapter 11 Firewall
LTE Series User’s Guide
127
The following table describes the labels in this screen.
11.7
Firewall Technical Reference
This section provides some technical background information about the topics covered in this chapter.
11.7.1
Firewall Rules Overview
Your customized rules take precedence and override the Zyxel Device’s default settings. The Zyxel
Device checks the source IP address, destination IP address and IP protocol type of network traffic
against the firewall rules (in the order you list them). When the traffic matches a rule, the Zyxel Device
takes the action specified in the rule.
Firewall rules are grouped based on the direction of travel of packets to which they apply:
By default, the Zyxel Device’s stateful packet inspection allows packets traveling in the following
directions:
LAN to Router
These rules specify which computers on the LAN can manage the Zyxel Device (remote
management).
Note: You can also configure the remote management settings to allow only a specific
computer to manage the Zyxel Device.
LAN to WAN
These rules specify which computers on the LAN can access which computers or services on the
WAN.
By default, the Zyxel Device’s stateful packet inspection drops packets traveling in the following
directions:
WAN to LAN
These rules specify which computers on the WAN can access which computers or services on the
LAN.
Note: You also need to configure NAT port forwarding (or full featured NAT address mapping
rules) to allow computers on the WAN to access devices on the LAN.
Table 47
Security > Firewall > DoS
LABEL
DESCRIPTION
DoS Protection
Blocking
Enable this to protect against DoS attacks. The Zyxel Device will drop sessions that surpass
maximum thresholds.
Apply
Click this to save your changes.
Cancel
Click this to restore your previously saved settings.
LAN to Router
WAN to LAN
LAN to WAN
WAN to Router