ZyXEL ZYWALL USG 100 User Guide - Page 110

How to Use an IPPBX on the DMZ

Page 110 highlights

Chapter 5 Managing Traffic 1 Click Configuration > Firewall > Add. In the From field select WAN. In the To field select LAN1. Configure a name for the rule (WAN-to-LAN_H323 here). Set the Destination to the H.323 device's LAN1 IP address object (LAN_H323). LAN_H323 is the destination because the ZyWALL applies NAT to traffic before applying the firewall rule. Set the Service to H.323. Click OK. 5.6.2 How to Use an IPPBX on the DMZ This is an example of making an IPPBX x6004 using SIP in the DMZ zone accessible from the Internet (the WAN zone). In this example you have public IP address 1.1.1.2 that you will use on the WAN interface and map to the IPPBX's private IP address of 192.168.3.9. The local SIP clients are on the LAN. Figure 44 IPPBX Example Network Topology 5.6.2.1 Turn On the ALG Click Configuration > Network > ALG. Select Enable SIP ALG and Enable SIP Transformations and click Apply. Figure 45 Configuration > Network > ALG 5.6.2.2 Set Up a NAT Policy for the IPPBX Click Configuration > Network > NAT > Add > Create New Object > Address and create an IPv4 host address object for the IPPBX's private DMZ IP address of 192.168.3.9. Repeat to create a host address object named IPPBX-Public for the public WAN IP address 1.1.1.2. • Configure a name for the rule (WAN-DMZ_IPPBX here). • You want the IPPBX to receive calls from the WAN and also be able to send calls to the WAN so you set the Classification to NAT 1:1. • Set the Incoming Interface to use the WAN interface. 110 ZyWALL USG100-PLUS User's Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140

Chapter 5 Managing Traffic
ZyWALL USG100-PLUS User’s Guide
110
1
Click
Configuration > Firewall
>
Add
.
In the
From
field select WAN.
In the
To
field select LAN1.
Configure a name for the rule (WAN-to-LAN_H323 here).
Set the
Destination
to the H.323 device’s LAN1 IP address object (
LAN_H323
).
LAN_H323
is
the destination because the ZyWALL applies NAT to traffic before applying the firewall rule.
Set the
Service
to
H.323
.
Click
OK
.
5.6.2
How to Use an IPPBX on the DMZ
This is an example of making an IPPBX x6004 using SIP in the DMZ zone accessible from the
Internet (the WAN zone). In this example you have public IP address 1.1.1.2 that you will use on
the WAN interface and map to the IPPBX’s private IP address of 192.168.3.9. The local SIP clients
are on the LAN.
Figure 44
IPPBX Example Network Topology
5.6.2.1
Turn On the ALG
Click
Configuration > Network > ALG
. Select
Enable SIP ALG
and
Enable SIP
Transformations
and click
Apply
.
Figure 45
Configuration > Network > ALG
5.6.2.2
Set Up a NAT Policy for the IPPBX
Click
Configuration > Network > NAT >
Add > Create New Object > Address
and create an
IPv4 host address object for the IPPBX’s private DMZ IP address of 192.168.3.9. Repeat to create a
host address object named IPPBX-Public for the public WAN IP address 1.1.1.2.
Configure a name for the rule (WAN-DMZ_IPPBX here).
You want the IPPBX to receive calls from the WAN and also be able to send calls to the WAN so
you set the
Classification
to
NAT 1:1
.
Set the
Incoming Interface
to use the WAN interface.