ZyXEL ZYWALL USG 100 User Guide - Page 108

What Can Go Wrong, 5.6 How to Manage Voice Traffic

Page 108 highlights

Chapter 5 Managing Traffic 5.5.3 What Can Go Wrong • The ZyWALL checks the firewall rules in order and applies the first firewall rule the traffic matches. If traffic matches a rule that comes earlier in the list, it may be unexpectedly blocked. • The ZyWALL does not apply the firewall rule. The ZyWALL only apply's a zone's rules to the interfaces that belong to the zone. Make sure the WAN interface is assigned to WAN zone. 5.6 How to Manage Voice Traffic Here are examples of allowing H.323 and SIP traffic through the ZyWALL. 5.6.1 How to Allow Incoming H.323 Peer-to-peer Calls Suppose you have a H.323 device on the LAN for VoIP calls and you want it to be able to receive peer-to-peer calls from the WAN. Here is an example of how to configure NAT and the firewall to have the ZyWALL forward H.323 traffic destined for WAN IP address 10.0.0.8 to a H.323 device located on the LAN and using IP address 192.168.1.56. Figure 42 WAN to LAN H.323 Peer-to-peer Calls Example 192.168.1.56 10.0.0.8 5.6.1.1 Turn On the ALG Click Configuration > Network > ALG. Select Enable H.323 ALG and Enable H.323 transformations and click Apply. 108 ZyWALL USG100-PLUS User's Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140

Chapter 5 Managing Traffic
ZyWALL USG100-PLUS User’s Guide
108
5.5.3
What Can Go Wrong
The ZyWALL checks the firewall rules in order and applies the first firewall rule the traffic
matches. If traffic matches a rule that comes earlier in the list, it may be unexpectedly blocked.
The ZyWALL does not apply the firewall rule. The ZyWALL only apply’s a zone’s rules to the
interfaces that belong to the zone. Make sure the WAN interface is assigned to WAN zone.
5.6
How to Manage Voice Traffic
Here are examples of allowing H.323 and SIP traffic through the ZyWALL.
5.6.1
How to Allow Incoming H.323 Peer-to-peer Calls
Suppose you have a H.323 device on the LAN for VoIP calls and you want it to be able to receive
peer-to-peer calls from the WAN. Here is an example of how to configure NAT and the firewall to
have the ZyWALL forward H.323 traffic destined for WAN IP address 10.0.0.8 to a H.323 device
located on the LAN and using IP address 192.168.1.56.
Figure 42
WAN to LAN H.323 Peer-to-peer Calls Example
5.6.1.1
Turn On the ALG
Click
Configuration > Network > ALG
. Select
Enable H.323 ALG
and
Enable H.323
transformations
and click
Apply
.
10.0.0.8
192.168.1.56