ZyXEL NBG-460N User Guide - Page 176

Security > Firewall > Services > Adding a Rule

Page 176 highlights

Chapter 13 Firewall Table 61 Security > Firewall > Services > Adding a Rule LABEL DESCRIPTION End IP Address Enter the ending IP address in a range here. This field is only available when IP Range is selected as the Address Type. IP Pool List Add an IP address from the IP Pool List to the Selected IP List by highlighting an IP address and clicking Add. To delete an IP address from the Selected IP List highlight an IP address and click the Remove button. These fields are only available when IP Pool is selected as the Address Type. The IP Pool list gathers its IPs from entries in the ARP table. The ARP table contains the IP addresses and MAC addresses of the devices that have sent traffic to the NBG-460N. Service Setup Available Services This is a list of pre-defined services (ports) you may prohibit your LAN computers from using. Select the port you want to block using the dropdown list and click Add to add the port to the Blocked Services field. Blocked Services This is a list of services (ports) that will be inaccessible to computers on your LAN once you enable service blocking. Custom Port A custom port is a service that is not available in the pre-defined Available Services list and you must define using the next two fields. Type Choose the IP port (TCP or UDP) that defines your customized port from the drop down list box. Port Number Enter the port number range that defines the service. For example, if you want to define the Gnutella service, then select TCP type and enter a port range from 6345 to 6349. Add Select a service from the Available Services drop-down list and then click Add to add a service to the Blocked Services. Delete Select a service from the Blocked Services list and then click Delete to remove this service from the list. Clear All Click Clear All to empty the Blocked Services. Schedule to Block Day to Block: Select a check box to configure which days of the week (or everyday) you want service blocking to be active. Time of Day to Block (24-Hour Format) Select the time of day you want service blocking to take effect. Configure blocking to take effect all day by selecting All Day. You can also configure specific times by selecting From and entering the start time in the Start (hour) and Start (min) fields and the end time in the End (hour) and End (min) fields. Enter times in 24-hour format, for example, "3:00pm" should be entered as "15:00". Log Active (Log packets match this rule) Select this to log packets that match this rule. Go to the Log Settings page and select the Access Control logs category to have the NBG460N record these logs. Misc setting Bypass Triangle Select this check box to have the NBG-460N firewall ignore the use of Route triangle route topology on the network. 176 NBG-460N User's Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370

Chapter 13 Firewall
NBG-460N User’s Guide
176
End IP Address
Enter the ending IP address in a range here. This field is only available
when
IP Range
is selected as the
Address Type
.
IP Pool List
Add an IP address from the
IP Pool List
to the
Selected IP List
by
highlighting an IP address and clicking
Add
. To delete an IP address
from the Selected IP List highlight an IP address and click the
Remove
button. These fields are only available when
IP Pool
is selected as the
Address Type
.
The
IP Pool list gathers its IPs from entries in the ARP table. The ARP
table contains the IP addresses and MAC addresses of the devices that
have sent traffic to the NBG-460N.
Service Setup
Available
Services
This is a list of pre-defined services (ports) you may prohibit your LAN
computers from using. Select the port you want to block using the drop-
down list and click
Add
to add the port to the
Blocked Services
field.
Blocked
Services
This is a list of services (ports) that will be inaccessible to computers on
your LAN once you enable service blocking.
Custom Port
A custom port is a service that is not available in the pre-defined
Available Services
list and you must define using the next two fields.
Type
Choose the IP port (
TCP
or
UDP
) that defines your customized port
from the drop down list box.
Port Number
Enter the port number range that defines the service. For example, if
you want to define the Gnutella service, then select
TCP
type and enter
a port range from 6345 to 6349.
Add
Select a service from the
Available Services
drop-down list and then
click
Add
to add a service to the
Blocked Services
.
Delete
Select a service from the
Blocked Services
list and then click
Delete
to remove this service from the list.
Clear All
Click
Clear All
to empty the
Blocked Services
.
Schedule to Block
Day to Block:
Select a check box to configure which days of the week (or everyday)
you want service blocking to be active.
Time of Day to
Block (24-Hour
Format)
Select the time of day you want service blocking to take effect.
Configure blocking to take effect all day by selecting
All Day
. You can
also configure specific times by selecting
From
and entering the start
time in the
Start (hour)
and
Start (min)
fields and the end time in
the
End (hour)
and
End (min)
fields. Enter times in 24-hour format,
for example, "3:00pm" should be entered as "15:00".
Log
Active (Log
packets match
this rule)
Select this to log packets that match this rule. Go to the
Log Settings
page and select the
Access Control
logs category to have the NBG-
460N record these logs.
Misc setting
Bypass Triangle
Route
Select this check box to have the NBG-460N firewall ignore the use of
triangle route topology on the network.
Table 61
Security > Firewall > Services > Adding a Rule
LABEL
DESCRIPTION