ZyXEL ZYWALL USG 100 User Guide - Page 119

Maintenance, 6.1 How to Allow Management Service from WAN, 6.1.1 Check Service Control - firmware download

Page 119 highlights

CHAPTER 6 Maintenance These sections cover managing and maintaining the ZyWALL. • How to Allow Management Service from WAN on page 119 • How to Use a RADIUS Server to Authenticate User Accounts based on Groups on page 122 • How to Use SSH for Secure Telnet Access on page 123 • How to Manage ZyWALL Configuration Files on page 124 • How to Manage ZyWALL Firmware on page 125 • How to Download and Upload a Shell Script on page 126 • How to Save System Logs to a USB Storage Device on page 127 • How to Get the ZyWALL's Diagnostic File on page 130 • How to Capture Packets on the ZyWALL on page 131 • How to Get the ZyWALL's Core Dump File on page 134 • How to Use Packet Flow Explore for Troubleshooting on page 135 6.1 How to Allow Management Service from WAN There are several ways that remote users can manage the ZyWALL: through WWW, SSH, Telnet, FTP, and SNMP. HTTPS and SSH access are more secure than others. To allow the ZyWALL to be accessed from a remote user using one of these services, make sure you do not have a service control rule or to-ZyWALL firewall rule to block this traffic. To allow a remote management service, you must ensure the following: • The service is enabled in its corresponding system screen (for example, you make sure the HTTPs service in the Configuration > System > WWW screen is enabled for it to work). • The allowed IP address (address object) in the Service Control table should match the client IP address. • The IP address (address object) in the Service Control table is in the allowed zone and the action is set to accept. • The to-ZyWALL firewall rules allow this traffic. The following example is used to check that administrators and users are allowed to access the ZyWALL from the WAN using HTTPs. 6.1.1 Check Service Control 1 Click Configuration > System > WWW. ZyWALL USG100-PLUS User's Guide 119

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140

ZyWALL USG100-PLUS User’s Guide
119
C
HAPTER
6
Maintenance
These sections cover managing and maintaining the ZyWALL.
How to Allow Management Service from WAN on page 119
How to Use a RADIUS Server to Authenticate User Accounts based on Groups on page 122
How to Use SSH for Secure Telnet Access on page 123
How to Manage ZyWALL Configuration Files on page 124
How to Manage ZyWALL Firmware on page 125
How to Download and Upload a Shell Script on page 126
How to Save System Logs to a USB Storage Device on page 127
How to Get the ZyWALL’s Diagnostic File on page 130
How to Capture Packets on the ZyWALL on page 131
How to Get the ZyWALL’s Core Dump File on page 134
How to Use Packet Flow Explore for Troubleshooting on page 135
6.1
How to Allow Management Service from WAN
There are several ways that remote users can manage the ZyWALL: through WWW, SSH, Telnet,
FTP, and SNMP. HTTPS and SSH access are more secure than others. To allow the ZyWALL to be
accessed from a remote user using one of these services, make sure you do not have a service
control rule or to-ZyWALL firewall rule to block this traffic.
To allow a remote management service, you must ensure the following:
The service is enabled in its corresponding system screen (for example, you make sure the
HTTPs service in the
Configuration > System > WWW
screen is enabled for it to work).
The allowed IP address (address object) in the
Service Control
table should match the client IP
address.
The IP address (address object) in the
Service Control
table is in the allowed zone and the
action is set to
accept
.
The to-ZyWALL firewall rules allow this traffic.
The following example is used to check that administrators and users are allowed to access the
ZyWALL from the WAN using HTTPs.
6.1.1
Check Service Control
1
Click
Configuration > System > WWW
.