Zyxel-communications ZYWALL10 Manuel d'utilisateur

Naviguer en ligne ou télécharger Manuel d'utilisateur pour Matériel Zyxel-communications ZYWALL10. ZyXEL Communications ZYWALL10 User Manual Manuel d'utilisatio

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 267
  • Table des matières
  • DEPANNAGE
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs

Résumé du contenu

Page 1 - ZyWALL 10

ZyWALL 10Internet Security GatewayUser’s GuideVersion 3.24April 2001

Page 2 - Copyright

ZyWALL 10 Internet Security Gatewayx Table of Contents2.7 General Setup...

Page 3 - (FCC) Interference Statement

ZyWALL 10 Internet Security GatewayFilters 7-1Chapter 7Filter ConfigurationThis chapter shows you how to create and apply filters.7.1 About FilteringY

Page 4

ZyWALL 10 Internet Security Gateway7-2 Filters7.1.1 The Filter Structure of the ZyWALLA filter set consists of one or more filter rules. Usually, yo

Page 5

ZyWALL 10 Internet Security GatewayFilters 7-3StartFetch FirstFilter SetFetch FirstFilter RuleActive?ExecuteFilter RuleFetch NextFilter RuleNext filte

Page 6

ZyWALL 10 Internet Security Gateway7-4 Filters7.2 Configuring a Filter SetTo configure a filter set, follow the procedure below. For more information

Page 7 - ZyXEL Limited Warranty

ZyWALL 10 Internet Security GatewayFilters 7-5Figure 7-6 NetBIOS_WAN Filter Rules SummaryFigure 7-7 NetBIOS _LAN Filter Rules SummaryFigure 7-8 TEL_FT

Page 8 - Customer Support

ZyWALL 10 Internet Security Gateway7-6 Filters7.2.1 Filter Rules Summary MenuThis screen shows the summary of the existing rules in the filter set.

Page 9 - Table of Contents

ZyWALL 10 Internet Security GatewayFilters 7-7ABBREVIATION DESCRIPTIONGENOff OffsetLen LengthRefer to the next section for information on configuring

Page 10

ZyWALL 10 Internet Security Gateway7-8 FiltersThe following table describes how to configure your TCP/IP filter rule.Table 7-3 TCP/IP Filter Rule Menu

Page 11

ZyWALL 10 Internet Security GatewayFilters 7-9FIELD DESCRIPTION OPTIONSaccording to the action fields.If More is Yes, then Action Matched and Action N

Page 12

ZyWALL 10 Internet Security Gateway7-10 FiltersThe following figure illustrates the logic flow of an IP filter.Packetinto IP FilterMatchedMatchedYesAc

Page 13

ZyWALL 10 Internet Security GatewayTable of Contents xi5.1 IP Static Route Setup...

Page 14

ZyWALL 10 Internet Security GatewayFilters 7-117.2.4 Generic Filter RuleThis section shows you how to configure a generic filter rule. The purpose o

Page 15

ZyWALL 10 Internet Security Gateway7-12 FiltersTable 7-4 Generic Filter Rule Menu FieldsFIELD DESCRIPTION OPTIONSFilter # This is the filter set, filt

Page 16

ZyWALL 10 Internet Security GatewayFilters 7-137.3 Example FilterLet’s look at an example to block outside users from telnetting into the ZyWALL. Plea

Page 17 - List of Figures

ZyWALL 10 Internet Security Gateway7-14 FiltersFigure 7-13 Example Filter — Menu 21.1.1.1When you press [ENTER] to confirm, you will see the following

Page 18

ZyWALL 10 Internet Security GatewayFilters 7-15Figure 7-14 Example Filter Rules Summary — Menu 21.1.3After you’ve created the filter set, you must app

Page 19

ZyWALL 10 Internet Security Gateway7-16 Filtersthe raw packets that appear on the wire. They are applied at the point when the ZyWALL is receiving and

Page 20

ZyWALL 10 Internet Security GatewayFilters 7-17Figure 7-16 Filtering LAN Traffic7.6.2 Remote Node FiltersGo to menu 11.5 (shown below – note that cal

Page 22

ZyWALL 10 Internet Security GatewaySNMP 8-1Chapter 8SNMP ConfigurationThis chapter discusses SNMP (Simple Network Management Protocol) for network man

Page 23 - List of Tables

ZyWALL 10 Internet Security Gateway8-2 SNMPThe following table describes the SNMP configuration parameters.Table 8-1 SNMP Configuration Menu FieldsFIE

Page 24

ZyWALL 10 Internet Security Gatewayxii Table of Contents7.6.2 Remote Node Filters...

Page 25

ZyWALL 10 Internet Security GatewaySystem Information & Diagnosis 9-1Chapter 9System Information & DiagnosisThis chapter covers SMT menus 24.

Page 26

ZyWALL 10 Internet Security Gateway9-2 System Information & DiagnosisFigure 9-2 Menu 24.1 — System Maintenance — StatusThe following table describ

Page 27

ZyWALL 10 Internet Security GatewaySystem Information & Diagnosis 9-3FIELD DESCRIPTIONIP Address The LAN port IP address.IP Mask The LAN port IP

Page 28

ZyWALL 10 Internet Security Gateway9-4 System Information & Diagnosis9.2.1 System InformationSystem Information gives you information about your s

Page 29 - Part I:

ZyWALL 10 Internet Security GatewaySystem Information & Diagnosis 9-59.2.2 Console Port SpeedYou can change the speed of the console port throug

Page 30

ZyWALL 10 Internet Security Gateway9-6 System Information & DiagnosisFigure 9-6 Menu 24.3 — System Maintenance — Log and TraceExamples of typical

Page 31 - Getting to Know Your ZyWALL

ZyWALL 10 Internet Security GatewaySystem Information & Diagnosis 9-7You need to configure the UNIX syslog parameters described in the following

Page 32

ZyWALL 10 Internet Security Gateway9-8 System Information & Diagnosis1. CDRCDR Message FormatSdcmdSyslogSend( SYSLOG_CDR, SYSLOG_INFO, String );S

Page 33

ZyWALL 10 Internet Security GatewaySystem Information & Diagnosis 9-9Mar 03 10:39:43 202.132.155.97 ZyXEL:GEN[fffffffffffnordff0080] }S05>R01m

Page 34

ZyWALL 10 Internet Security Gateway9-10 System Information & Diagnosis9.3.3 Call-Triggering PacketCall-Triggering Packet displays information abou

Page 35 - Chapter 2

ZyWALL 10 Internet Security GatewayTable of Contents xiii11.2 Call Control Support ...

Page 36

ZyWALL 10 Internet Security GatewaySystem Information & Diagnosis 9-11Figure 9-10 Menu 24.4 — System Maintenance — DiagnosticFollow the procedure

Page 37

ZyWALL 10 Internet Security Gateway9-12 System Information & DiagnosisFigure 9-11 WAN & LAN DHCPThe following table describes the diagnostic t

Page 38 - 2.4 Turn On Your ZyWALL

ZyWALL 10 Internet Security GatewayFirmware and Configuration File Maintenance 10-1Chapter 10Firmware and Configuration FileMaintenanceThis chapter t

Page 39 - Table 2-2 Main Menu Commands

ZyWALL 10 Internet Security Gateway10-2 Firmware and Configuration File MaintenanceTable 10-1 Filename ConventionsFILE TYPE INTERNALNAMEEXTERNALNAMEDE

Page 40 - 2.5.1 Main Menu

ZyWALL 10 Internet Security GatewayFirmware and Configuration File Maintenance 10-310.2.1 Example: Backup Configuration Using HyperTerminalThis secti

Page 41 - Table 2-3 Main Menu Summary

ZyWALL 10 Internet Security Gateway10-4 Firmware and Configuration File Maintenance10.3 Restore ConfigurationMenu 24.6 -- System Maintenance - Restore

Page 42 - 2.5.3 SMT Menus at a Glance

ZyWALL 10 Internet Security GatewayFirmware and Configuration File Maintenance 10-5Figure 10-8 Telnet into Menu 24.6 Restore Configuration10.4 Upload

Page 43 - 2.7 General Setup

ZyWALL 10 Internet Security Gateway10-6 Firmware and Configuration File MaintenanceStep 4. After successful firmware upload, enter atgo to restart th

Page 44 - 2.7.1 Dynamic DNS

ZyWALL 10 Internet Security GatewayFirmware and Configuration File Maintenance 10-7Menu 24.6 replaces the current configuration with your customized

Page 45

ZyWALL 10 Internet Security Gateway10-8 Firmware and Configuration File MaintenanceStep 1. Use telnet from your workstation to connect to the ZyWALL

Page 46 - 2.8 WAN Setup

ZyWALL 10 Internet Security Gatewayxiv Table of Contents14.1 SMT Menus...

Page 47 - 2.9 LAN Setup

ZyWALL 10 Internet Security GatewayFirmware and Configuration File Maintenance 10-9COMMAND DESCRIPTIONRemote File This is the filename on the ZyWALL.

Page 48 - 2.9.1 LAN Port Filter Setup

ZyWALL 10 Internet Security Gateway10-10 Firmware and Configuration File MaintenanceFigure 10-13 Telnet into Menu 24.7.1You see the following screen w

Page 49 - Internet Access

ZyWALL 10 Internet Security GatewayFirmware and Configuration File Maintenance 10-1110.6.1 Using the FTP command from the DOS PromptStep 1. Launch t

Page 50 - 3.1.4 Private IP Addresses

ZyWALL 10 Internet Security Gateway10-12 Firmware and Configuration File MaintenanceTable 10-3 Third Party FTP Clients — General FieldsCOMMAND DESCRIP

Page 51 - 3.1.6 IP Multicast

ZyWALL 10 Internet Security GatewaySystem Maintenance & Information 11-1Chapter 11 System Maintenance & InformationThis chapter leads you thr

Page 52 - 3.1.7 IP Alias

ZyWALL 10 Internet Security Gateway11-2 System Maintenance & Information11.2 Call Control SupportThe ZyWALL provides two call control functions: b

Page 53

ZyWALL 10 Internet Security GatewaySystem Maintenance & Information 11-3The total budget is the time limit on the accumulated time for outgoing c

Page 54 - 3-6 Internet Access

ZyWALL 10 Internet Security Gateway11-4 System Maintenance & InformationFigure 11-5 Call HistoryTable 11-2 Call History FieldsFIELD DESCRIPTIONPho

Page 55 - 3.2.1 IP Alias Setup

ZyWALL 10 Internet Security GatewaySystem Maintenance & Information 11-5Select menu 24 in the main menu to open Menu 24 - System Maintenance, as

Page 56 - 3.3 Internet Access Setup

ZyWALL 10 Internet Security Gateway11-6 System Maintenance & InformationTable 11-3 Time and Date Setting FieldsFIELD DESCRIPTIONEnter the time ser

Page 57 - Internet Access 3-9

ZyWALL 10 Internet Security GatewayTable of Contents xv17.1 Introduction...

Page 58 - 3.3.2 PPTP Encapsulation

ZyWALL 10 Internet Security GatewaySystem Maintenance & Information 11-711.4 Remote Management SetupTelnet and FTP do not support encryption, so

Page 59 - 3.3.4 PPPoE Encapsulation

ZyWALL 10 Internet Security Gateway11-8 System Maintenance & Information11.5 Boot CommandsThe BootModule AT commands execute from within the route

Page 60

ZyWALL 10 Internet Security GatewaySystem Maintenance & Information 11-9Figure 11-10 Boot Module Commands======= Debug Command Listing =======AT

Page 62 - Part II:

ZyWALL 10 Internet Security GatewayTelnet 12-1Chapter 12Telnet Configuration and CapabilitiesThis chapter covers the Telnet Configuration and Capabil

Page 63 - Remote Node Setup

ZyWALL 10 Internet Security Gateway12-2 Telnet12.3.2 System TimeoutThere is a system timeout of 5 minutes (300 seconds) for either the console port or

Page 64 - Table 4-1 Fields in Menu 11.1

Firewall and Content FiltersIVPart IV: Firewall and Content FiltersChapters 13 — 20 define the term “Firewall”, introduce the ZyWALL Firewall and ZyWA

Page 66 - 4.1.3 PPTP Encapsulation

ZyWALL 10 Internet Security GatewayWhat Is a Firewall? 13-1Chapter 13What is a Firewall?This chapter gives some background information on Firewalls.O

Page 67 - Remote Node Setup 4-5

ZyWALL 10 Internet Security Gateway13-2 What Is a Firewall?ii. Robust authentication and logging pre-authenticates application traffic before it re

Page 68

ZyWALL 10 Internet Security Gatewayxvi Table of ContentsAppendix E Firewall CLI Commands ...

Page 69

ZyWALL 10 Internet Security GatewayWhat Is a Firewall? 13-3Figure 13-1 ZyWALL Firewall Application13.3 Denial of ServiceDenials of Service (DoS) at

Page 70 - 4-8 Remote Node Setup

ZyWALL 10 Internet Security Gateway13-4 What Is a Firewall?Some of the most common IP ports are:Table 13-1 Common IP Ports21 FTP 53 DNS23 Telnet 80

Page 71 - 4.3 Remote Node Filter

ZyWALL 10 Internet Security GatewayWhat Is a Firewall? 13-5Figure 13-2 Three-Way HandshakeUnder normal circumstances, the application that initiates

Page 72 - 4-10 Remote Node Setup

ZyWALL 10 Internet Security Gateway13-6 What Is a Firewall?3. A brute-force attack, such as a "Smurf" attack, targets a feature in the IP

Page 73 - IP Static Route Setup

ZyWALL 10 Internet Security GatewayWhat Is a Firewall? 13-7! Denies all sessions originating from the WAN (Internet) to the LAN (local network).Figur

Page 74 - 5.1 IP Static Route Setup

ZyWALL 10 Internet Security Gateway13-8 What Is a Firewall?6. Later, an inbound packet reaches the interface. This packet is part of the connection

Page 75 - IP Static Route Setup 5-3

ZyWALL 10 Internet Security GatewayWhat Is a Firewall? 13-9If an initiation packet originates on the LAN, this means that someone is trying to make a

Page 76

ZyWALL 10 Internet Security Gateway13-10 What Is a Firewall?2. Think about access control before you connect a console port to the network in any w

Page 77 - Chapter 6

ZyWALL 10 Internet Security GatewayWhat Is a Firewall? 13-118. Change your passwords regularly. Also, use passwords that are not easy to figure out.

Page 79 - 6.1.4 NAT Mapping Types

ZyWALL 10 Internet Security GatewayList of Figures xviiList of FiguresFigure 1-1 Secure Internet Access via Cable ...

Page 80 - 6.1.6 NAT Application

ZyWALL 10 Internet Security GatewayIntroducing the ZyWALL Firewall 14-1Chapter 14Introducing the ZyWALL FirewallThis chapter shows you how to get star

Page 81 - 6.2 SMT Menus

ZyWALL 10 Internet Security Gateway14-2 Introducing the ZyWALL FirewallFigure 14-3 Menu 21.2 — Firewall SetupConfigure the firewall rules using the Z

Page 82

ZyWALL 10 Internet Security GatewayIntroducing the ZyWALL Firewall 14-3ICMP EchoA brute-force attack, such as a "Smurf" attack, targets a fe

Page 83 - 6.2.2 Configuring NAT

ZyWALL 10 Internet Security Gateway14-4 Introducing the ZyWALL FirewallTracerouteTraceroute is a utility used to determine the path a packet takes be

Page 84

ZyWALL 10 Internet Security GatewayIntroducing the ZyWALL Firewall 14-5Table 14-4 View Firewall LogFIELD DESCRIPTION EXAMPLES# This is the index numbe

Page 85

ZyWALL 10 Internet Security Gateway14-6 Introducing the ZyWALL FirewallFigure 14-5 Big Picture — Filtering, Firewall and NAT14.3 Packet Filtering Vs

Page 86

ZyWALL 10 Internet Security GatewayIntroducing the ZyWALL Firewall 14-7When To Use Filtering1. To block/allow LAN packets by their MAC address.2. To

Page 88 - 6.3 NAT Server Sets

ZyWALL 10 Internet Security GatewayIntroducing the ZyWALL Web Configurator 15-1Chapter 15Introducing the ZyWALL Web ConfiguratorThis chapter shows you

Page 89

ZyWALL 10 Internet Security Gateway15-2 Introducing the ZyWALL Web ConfiguratorFigure 15-2 ZyWALL Web Configurator Welcome Screen

Page 90 - 1026 entry

ZyWALL 10 Internet Security Gatewayxviii List of FiguresFigure 4-4 Menu 11.3 — Remote Node Network Layer Options...

Page 91 - 6.4 Examples

ZyWALL 10 Internet Security GatewayIntroducing the ZyWALL Web Configurator 15-315.2 Enabling the FirewallClick Firewall, then Configuration, then the

Page 92

ZyWALL 10 Internet Security Gateway15-4 Introducing the ZyWALL Web Configuratormail account. Enter the complete e-mail address to which alert message

Page 93

ZyWALL 10 Internet Security GatewayIntroducing the ZyWALL Web Configurator 15-5Table 15-1 E-mailFIELD DESCRIPTION OPTIONSAddress InformationMail Serve

Page 94

ZyWALL 10 Internet Security Gateway15-6 Introducing the ZyWALL Web Configurator15.3.3 SMTP Error MessagesIf there are difficulties in sending e-mail

Page 95

ZyWALL 10 Internet Security GatewayIntroducing the ZyWALL Web Configurator 15-7Figure 15-5 E-mail Log15.4 Attack AlertThe first defense against DOS at

Page 96

ZyWALL 10 Internet Security Gateway15-8 Introducing the ZyWALL Web Configurator5. Type of traffic for certain servers.If your network is slower than

Page 97 - NAT 6-21

ZyWALL 10 Internet Security GatewayIntroducing the ZyWALL Web Configurator 15-9Figure 15-6 Attack AlertThe following table describes the fields in thi

Page 98 - Part III:

ZyWALL 10 Internet Security Gateway15-10 Introducing the ZyWALL Web ConfiguratorTable 15-3 Attack AlertFIELD DESCRIPTION DEFAULT VALUESGenerate alert

Page 99

ZyWALL 10 Internet Security GatewayIntroducing the ZyWALL Web Configurator 15-11FIELD DESCRIPTION DEFAULT VALUESrises above this number, the ZyWALLdel

Page 101

ZyWALL 10 Internet Security GatewayList of Figures xixFigure 6-21 NAT Example 4...

Page 102 - Filter Set

ZyWALL 10 Internet Security GatewayCreating Custom Rules 16-1Chapter 16Creating Custom RulesThis chapter contains instructions for defining both Local

Page 103 - 7.2 Configuring a Filter Set

ZyWALL 10 Internet Security Gateway16-2 Creating Custom Rules5. What computers on the LAN are to be affected (if any)?6. What computers on the Inte

Page 104 - Filters 7-5

ZyWALL 10 Internet Security GatewayCreating Custom Rules 16-316.3 Connection DirectionThis section talks about configuring firewall rules for connecti

Page 105

ZyWALL 10 Internet Security Gateway16-4 Creating Custom RulesFigure 16-2 WAN to LAN Traffic16.4 Rule SummaryThe fields in the Rule Summary screens ar

Page 106 - 7.2.3 TCP/IP Filter Rule

ZyWALL 10 Internet Security GatewayCreating Custom Rules 16-5Figure 16-3 Firewall Rules Summary — First ScreenThe following table describes the fields

Page 107 - 7-8 Filters

ZyWALL 10 Internet Security Gateway16-6 Creating Custom RulesTable 16-1 Firewall Rules Summary — First ScreenFIELD DESCRIPTION OPTIONSGeneralName Thi

Page 108 - Filters 7-9

ZyWALL 10 Internet Security GatewayCreating Custom Rules 16-7FIELD DESCRIPTION OPTIONSClick Apply to create a new firewall rule. New firewall rules ar

Page 109 - 7-10 Filters

ZyWALL 10 Internet Security Gateway16-8 Creating Custom RulesTable 16-2 Predefined ServicesSERVICE DESCRIPTIONBGP(TCP:179) Border Gateway Protocol.BO

Page 110 - 7.2.4 Generic Filter Rule

ZyWALL 10 Internet Security GatewayCreating Custom Rules 16-9SERVICE DESCRIPTIONSFTP(TCP:115) Simple File Transfer Protocol.SMTP(TCP:25) Simple Mail T

Page 111 - 7-12 Filters

ZyWALL 10 Internet Security Gateway16-10 Creating Custom Rules16.5.1 Creating/Editing Firewall RulesTo create a new rule, click a number (No.) then c

Page 112 - 7.3 Example Filter

ZyWALL 10 Internet Security Gatewayii CopyrightCopyrightCopyright © 2001 by ZyXEL Communications Corporation.The contents of this publication may not

Page 113

ZyWALL 10 Internet Security Gatewayxx List of FiguresFigure 9-8 Menu 24.3.2 — System Maintenance — UNIX Syslog...

Page 114 - 7.4 Filter Types and NAT

ZyWALL 10 Internet Security GatewayCreating Custom Rules 16-11Table 16-3 Creating/Editing A Firewall RuleFIELD DESCRIPTION OPTIONSSource AddressPress

Page 115 - 7.5 Firewall

ZyWALL 10 Internet Security Gateway16-12 Creating Custom Rules16.5.2 Source and Destination AddressesTo add a new source or destination address, clic

Page 116 - 7.6.2 Remote Node Filters

ZyWALL 10 Internet Security GatewayCreating Custom Rules 16-13Table 16-4 Adding/Editing Source and Destination AddressesFIELD DESCRIPTION OPTIONSAddre

Page 117

ZyWALL 10 Internet Security Gateway16-14 Creating Custom Rules16.6 TimeoutThe fields in the Timeout screens are the same for Local and Internet netwo

Page 118 - SNMP Configuration

ZyWALL 10 Internet Security GatewayCreating Custom Rules 16-15Table 16-5 Timeout MenuFIELD DESCRIPTION DEFAULTVALUETCP Timeout ValuesConnection Timeou

Page 120 - Chapter 9

ZyWALL 10 Internet Security GatewayCustom Ports 17-1Chapter 17Custom PortsThis chapter covers creating, viewing and editing custom ports.17.1 Introduc

Page 121

ZyWALL 10 Internet Security Gateway17-2 Custom PortsTable 17-1 Custom PortsFIELD DESCRIPTIONCustomizedServicesNo. This is the number of your customiz

Page 122 - 2. Console Port Speed

ZyWALL 10 Internet Security GatewayCustom Ports 17-317.2 Creating/Editing A Custom PortClick Edit to create a new custom port or edit an existing one

Page 123 - 9.2.1 System Information

ZyWALL 10 Internet Security Gateway17-4 Custom PortsTable 17-2 Creating/Editing A Custom PortFIELD DESCRIPTION OPTIONSService Name Enter a unique nam

Page 124 - 9.3 Log and Trace

ZyWALL 10 Internet Security GatewayList of Figures xxiFigure 12-1 Telnet Configuration on a TCP/IP Network...

Page 125 - 9.3.2 UNIX Syslog

ZyWALL 10 Internet Security GatewayExample Firewall Rules 18-1Chapter 18LogsThis chapter contains information about using the log screen to view the r

Page 126

ZyWALL 10 Internet Security Gateway18-2 Example Firewall RulesTable 18-1 Log ScreenFIELD DESCRIPTION EXAMPLESNo. This is the index number of the fire

Page 127 - 3. Filter log

ZyWALL 10 Internet Security GatewayExample Firewall Rules 19-1Chapter 19Example Firewall RulesThis chapter gives examples for configuring various rule

Page 128 - 5. Firewall log

ZyWALL 10 Internet Security Gateway19-2 Example Firewall RulesStep 1. Activate the firewall. You may activate the firewall through the ZyWALL Web Co

Page 129 - 9.4 Diagnostic

ZyWALL 10 Internet Security GatewayExample Firewall Rules 19-3Step 2. Configure your E-mail screen as follows. Click the E-mail tab to bring up the n

Page 130 - 9.4.1 WAN DHCP

ZyWALL 10 Internet Security Gateway19-4 Example Firewall RulesStep 3. Configure your firewall rule as shown in the following screen. The default fir

Page 131

ZyWALL 10 Internet Security GatewayExample Firewall Rules 19-5Step 4. Click DestAdd to configure the destination address as the IP of your server on

Page 132 - Maintenance

ZyWALL 10 Internet Security Gateway19-6 Example Firewall RulesStep 5. When you have finished configuring your rules, the Rule Summary screen should

Page 133 - 10.2 Backup Configuration

ZyWALL 10 Internet Security GatewayExample Firewall Rules 19-7Step 1. First you want to send alerts when there is an attack. Go to the Attack Alert s

Page 134

ZyWALL 10 Internet Security Gateway19-8 Example Firewall RulesFigure 19-7 Configuring A POP Custom PortStep 4. Now, you will create rules to block a

Page 135 - 10.3 Restore Configuration

ZyWALL 10 Internet Security Gatewayxxii List of FiguresFigure 19-2 Example 1: E-mail Screen...

Page 136 - 10.4 Upload Firmware

ZyWALL 10 Internet Security GatewayExample Firewall Rules 19-9Step 5. Click SrcAdd under the Source Address box and enter the IP address of the mail

Page 137

ZyWALL 10 Internet Security Gateway19-10 Example Firewall RulesStep 7. The Rule Summary screen should look like Figure 19-9. Don’t forget to click A

Page 138 - 10.5 TFTP File Transfer

ZyWALL 10 Internet Security GatewayExample Firewall Rules 19-11Step 9. On completing the procedure the Rule Summary for this Internet firewall rules

Page 139 - 10.5.1 Example: TFTP Command

ZyWALL 10 Internet Security Gateway19-12 Example Firewall Rules19.1.3 Example 3: DHCP Negotiation and Syslog Connection from theInternetThe following

Page 140 - 10.6 FTP File Transfer

ZyWALL 10 Internet Security GatewayExample Firewall Rules 19-13Step 2. Follow the procedures outlined in the previous examples to configure all your

Page 141

ZyWALL 10 Internet Security Gateway19-14 Example Firewall RulesStep 3. On completing the procedure the Rule Summary for this Internet firewall rules

Page 142

ZyWALL 10 Internet Security GatewayContent Filtering 20-1Chapter 20Content FilteringThis chapter provides a brief overview of content filtering using

Page 143

ZyWALL 10 Internet Security Gateway20-2 Content FilteringFigure 20-1 Categories Screen

Page 144 - Chapter 11

ZyWALL 10 Internet Security GatewayContent Filtering 20-320.2 Update ListContent on the Internet is constantly changing, so the content filter list sh

Page 145 - 11.2 Call Control Support

ZyWALL 10 Internet Security Gateway20-4 Content Filtering20.3 Exempting ComputersThis screen allows the administrator to include or exclude a range o

Page 146 - 11.2.2 Call History

ZyWALL 10 Internet Security GatewayList of Tables xxiiiList of TablesTable 2-1 LED functions ...

Page 147 - 11.3 Time and Date Setting

ZyWALL 10 Internet Security GatewayContent Filtering 20-520.4 CustomizingCustomize the content filter list by adding or removing specific sites from t

Page 148

ZyWALL 10 Internet Security Gateway20-6 Content Filtering20.5 KeywordsThe ZyWALL can also be configured to block certain web sites by using URL keywo

Page 149

ZyWALL 10 Internet Security GatewayContent Filtering 20-720.6 Log RecordsThis screen records the results of your content filter policies.Figure 20-6 L

Page 150 - 11.4 Remote Management Setup

Troubleshooting, Appendices, Glossary and IndexVPart V: Troubleshooting, Appendices, Glossary and IndexChapter 21 provides information about solving c

Page 152

ZyWALL 10 Internet Security GatewayTroubleshooting 21-1Chapter 21TroubleshootingThis chapter covers potential problems and possible remedies. After e

Page 153

ZyWALL 10 Internet Security Gateway21-2 Troubleshooting21.2 Problems with the LAN InterfaceTable 21-2 Troubleshooting the LAN InterfaceProblem Corre

Page 154 - Chapter 12

ZyWALL 10 Internet Security GatewayTroubleshooting 21-321.4 Problems with Internet AccessTable 21-4 Troubleshooting Internet AccessProblem Corrective

Page 156 - Part IV:

ZyWALL 10 Internet Security GatewayPPPoE AAppendix APPPoEPPPoE in ActionAn ADSL modem bridges a PPP session over Ethernet (PPP over Ethernet, RFC 2516

Page 157

ZyWALL 10 Internet Security Gatewayxxiv List of TablesTable 7-2 Rule Abbreviations Used ...

Page 158 - What is a Firewall?

ZyWALL 10 Internet Security GatewayPPPoEBHow PPPoE WorksThe PPPoE driver makes the Ethernet appear as a serial link to the PC and the PC runs PPP over

Page 159

ZyWALL 10 Internet Security GatewayPPTP CAppendix B PPTPWhat is PPTP?PPTP (Point-to-Point Tunneling Protocol) is a Microsoft proprietary protocol (RFC

Page 160 - 13.3 Denial of Service

ZyWALL 10 Internet Security Gateway PPTPDAccess Concentrator) and the PPTP user. The PNS is the box that hosts both the PPP and the PPTP stacksand

Page 161 - 13.3.2 Types of DoS attacks

ZyWALL 10 Internet Security GatewayHardware Specifications EAppendix CHardware SpecificationsPower Specification I/P AC 120V / 60Hz ; O/P DC 12V 1200

Page 162

ZyWALL 10 Internet Security GatewayF Safety InstructionsAppendix DImportant Safety InstructionsThe following safety instructions apply to the ZyWALL.1

Page 163 - 13.4 Stateful Inspection

ZyWALL 10 Internet Security GatewayCLI Commands GAppendix EFirewall CLI CommandsThe following table describes the syntax used to configure your firewa

Page 164

ZyWALL 10 Internet Security GatewayH CLI CommandsFunction CLI Syntax Descriptionconfig edit firewall e-mailemail-to<e-mail address>Edits the mai

Page 165 - 13.4.3 TCP Security

ZyWALL 10 Internet Security GatewayCLI Commands IFunction CLI Syntax DescriptionConfig edit firewall set <set #>default-permit <forward | blo

Page 166 - 13.4.5 Upper Layer Protocols

ZyWALL 10 Internet Security GatewayJ CLI CommandsFunction CLI Syntax Descriptionconfig edit firewall set <set #>rule<rule #> srcaddr-subne

Page 167 - 13.5.1 Security In General

ZyWALL 10 Internet Security GatewayCLI Commands KFunction CLI Syntax DescriptionDDeelleetteeconfig delete firewall e-mailRemoves all the settings for

Page 168

ZyWALL 10 Internet Security GatewayList of Tables xxvTable 17-1 Custom Ports...

Page 169

ZyWALL 10 Internet Security GatewayL Power Adapter SpecificationsAppendix FPower Adapter SpecificationsAC Power Adapter SpecificationsNorth AmericaAC

Page 170 - Chapter 14

ZyWALL 10 Internet Security GatewayPower Adapter Specifications MJapanAC Power Adapter model JOD-48-1124Input power: AC100Volts/ 50/60Hz/ 27VAOutput p

Page 171 - 14.1.2 Attack Types

ZyWALL 10 Internet Security GatewayN Glossary of TermsGlossary of Terms10BaseTThe 10-Mbps baseband Ethernet specification that uses two pairs of twist

Page 172

ZyWALL 10 Internet Security GatewayGlossary of Terms OCookie A string of characters saved by a web browser on the user's hard disk. Many web page

Page 173

ZyWALL 10 Internet Security GatewayP Glossary of TermsDigital Signature Digital code that authenticates whomever signed the document or software. Soft

Page 174 - Table 14-4 View Firewall Log

ZyWALL 10 Internet Security GatewayGlossary of Terms QEvents These are network activities. Some activities are direct attacks on your system, whileoth

Page 175 - 14.3.1 Packet Filtering:

ZyWALL 10 Internet Security GatewayR Glossary of TermsIntegrity Proof that the data is the same as originally intended. Unauthorized software or peopl

Page 176 - 14.3.2 Firewall

ZyWALL 10 Internet Security GatewayGlossary of Terms Ssame as your Ethernet address.) The MAC layer frames data for transmission over thenetwork, then

Page 177

ZyWALL 10 Internet Security GatewayT Glossary of TermsThis category of computer criminal includes several different types of illegal activitiesMaking

Page 178 - Chapter 15

ZyWALL 10 Internet Security GatewayGlossary of Terms UProxy Server A server that performs network operations in lieu of other systems on the network.P

Page 180 - 15.3 E-mail

ZyWALL 10 Internet Security GatewayV Glossary of Termssecurity flaws in their network systems.ServerA computer, or a software package, that provides a

Page 181 - 15.3.2 What are Logs?

ZyWALL 10 Internet Security GatewayGlossary of Terms WTFTPTrivial File Transfer Protocol is an Internet file transfer protocol similar to FTP (FileTra

Page 183 - 15.3.4 Example E-mail Log

ZyWALL 10 Internet Security GatewayIndex YIndexAAction for Matched Packets... 16-11Activate The Firewall ...

Page 184 - 15.4 Attack Alert

ZyWALL 10 Internet Security GatewayZ IndexE-mail tab...15-4EncapsulationPPP over Ethernet...

Page 185 - 15.4.2 Half-Open Sessions

ZyWALL 10 Internet Security GatewayIndex AARule Summary ... 16-4log...

Page 186 - Figure 15-6 Attack Alert

ZyWALL 10 Internet Security GatewayBB IndexSecurity Ramifications...16-2Send Alerts When Attacked ...

Page 187 - Table 15-3 Attack Alert

ZyWALL 10 Internet Security GatewayIndex CCXxDSL modem... 1-3, 1-4, 2-3, 2-4, 4-3, 21-2, 21-3XMODEM protocol...

Page 188

ZyWALL 10 Internet Security GatewayPreface xxviiPrefaceAbout Your RouterCongratulations on your purchase of the ZyWALL 10 Internet Security Gateway.Do

Page 189

ZyWALL 10 Internet Security Gatewayxxviii PrefaceRegardless of your particular application, it is important that you follow the steps outlined in Cha

Page 190 - Creating Custom Rules

Getting StartedIPart I: Getting StartedChapters 1— 3 are structured as a step-by-step guide to help you connect, install and setup yourZyWALL to opera

Page 191 - 16.2.2 Security Ramifications

ZyWALL 10 Internet Security GatewayFCC iiiFederal Communications Commission(FCC) Interference StatementThis device complies with Part 15 of FCC rules.

Page 193 - 16.4 Rule Summary

ZyWALL 10 Internet Security GatewayGetting to Know Your ZyWALL 1-1Chapter 1Getting to Know Your ZyWALLThis chapter introduces the main features and a

Page 194 - Creating Custom Rules 16-5

ZyWALL 10 Internet Security Gateway1-2 Getting to Know Your ZyWALLPPTP EncapsulationPoint-to-Point Tunneling Protocol (PPTP) is a network protocol tha

Page 195 - 16-6 Creating Custom Rules

ZyWALL 10 Internet Security GatewayGetting to Know Your ZyWALL 1-3Full Network ManagementThis feature allows you to access the SMT (System Management

Page 196 - 16.5 Predefined Services

ZyWALL 10 Internet Security Gateway1-4 Getting to Know Your ZyWALLFigure 1-1 Secure Internet Access via CableFigure 1-2 Secure Internet Access via DSL

Page 197 - 16-8 Creating Custom Rules

ZyWALL 10 Internet Security GatewayHardware Installation & Initial Setup 2-1Chapter 2Hardware Installation & Initial SetupThis chapter explai

Page 198 - Creating Custom Rules 16-9

ZyWALL 10 Internet Security Gateway2-2 Hardware Installation & Initial SetupLEDS FUNCTION INDICATORSTATUSACTIVE DESCRIPTIONOff The WAN Link is not

Page 199 - 16-10 Creating Custom Rules

ZyWALL 10 Internet Security GatewayHardware Installation & Initial Setup 2-3console port of the ZyWALL and the other end (choice of 9-pin or 25-

Page 200 - Creating Custom Rules 16-11

ZyWALL 10 Internet Security Gateway2-4 Hardware Installation & Initial Setup3. A cable/xDSL modem and an ISP account.After the ZyWALL is properly

Page 201

ZyWALL 10 Internet Security GatewayHardware Installation & Initial Setup 2-5Several operations that you should be familiar with before you attemp

Page 202 - Creating Custom Rules 16-13

ZyWALL 10 Internet Security Gatewayiv Canadian UsersInformation for Canadian UsersThe Industry Canada label identifies certified equipment. This certi

Page 203 - 16.6 Timeout

ZyWALL 10 Internet Security Gateway2-6 Hardware Installation & Initial Setup2.5.1 Main MenuAfter you enter the password, the SMT displays the ZyWA

Page 204 - Table 16-5 Timeout Menu

ZyWALL 10 Internet Security GatewayHardware Installation & Initial Setup 2-72.5.2 System Management Terminal Interface SummaryTable 2-3 Main Men

Page 205

ZyWALL 10 Internet Security Gateway2-8 Hardware Installation & Initial Setup2.5.3 SMT Menus at a GlanceFigure 2-6 SMT Menus at a Glance

Page 206 - Custom Ports

ZyWALL 10 Internet Security GatewayHardware Installation & Initial Setup 2-92.6 Changing the System PasswordThe first thing you should do is cha

Page 207 - Table 17-1 Custom Ports

ZyWALL 10 Internet Security Gateway2-10 Hardware Installation & Initial SetupThe Domain Name entry is what is propagated to the DHCP clients on th

Page 208

ZyWALL 10 Internet Security GatewayHardware Installation & Initial Setup 2-11Table 2-4 General Setup Menu FieldFIELD DESCRIPTION EXAMPLESystem Na

Page 209 - 17-4 Custom Ports

ZyWALL 10 Internet Security Gateway2-12 Hardware Installation & Initial SetupTable 2-5 Configure Dynamic DNS Menu FieldsFIELD DESCRIPTION EXAMPLES

Page 210 - Chapter 18

ZyWALL 10 Internet Security GatewayHardware Installation & Initial Setup 2-13Figure 2-10 Menu 2 — WAN SetupThe MAC address field allows users to

Page 211 - Table 18-1 Log Screen

ZyWALL 10 Internet Security Gateway2-14 Hardware Installation & Initial SetupFigure 2-11 Menu 3 — LAN Setup2.9.1 LAN Port Filter SetupThis menu a

Page 212 - Example Firewall Rules

ZyWALL 10 Internet Security GatewayInternet Access 3-1Chapter 3Internet AccessThis chapter shows you how to configure the LAN as well as the WAN of y

Page 213

ZyWALL 10 Internet Security GatewayDeclaration of Conformity vDeclaration of ConformityWe, the Manufacturer/Importer,ZyXEL Communications Corp.No. 6,

Page 214

ZyWALL 10 Internet Security Gateway3-2 Internet AccessExample of network properties for LAN servers with fixed IP addresses:Choose an IP address:192.1

Page 215

ZyWALL 10 Internet Security GatewayInternet Access 3-3Internet addresses for your local networks. On the other hand, if you are part of a much larger

Page 216

ZyWALL 10 Internet Security Gateway3-4 Internet AccessWAN interfaces using menus 3.2 (LAN) and 11.3 (WAN). Select None to disable IP Multicasting on t

Page 217

ZyWALL 10 Internet Security GatewayInternet Access 3-5Figure 3-3 Menu 3 — LAN SetupFrom menu 3, select the submenu option TCP/IP and DHCP Setup and p

Page 218

ZyWALL 10 Internet Security Gateway3-6 Internet AccessTable 3-1 DHCP Ethernet Setup Menu FieldsFIELD DESCRIPTION EXAMPLEDHCP This field enables/disabl

Page 219

ZyWALL 10 Internet Security GatewayInternet Access 3-7FIELD DESCRIPTION EXAMPLEMulticast IGMP (Internet Group Multicast Protocol) is a session-layer

Page 220

ZyWALL 10 Internet Security Gateway3-8 Internet AccessUse the instructions in the following table to configure IP Alias parameters.Table 3-3 IP Alias

Page 221

ZyWALL 10 Internet Security GatewayInternet Access 3-9Figure 3-6 Menu 4 — Internet Access Setup (Ethernet)The following table describes this screen.T

Page 222

ZyWALL 10 Internet Security Gateway3-10 Internet AccessFIELD DESCRIPTIONIP Address Enter the (fixed) IP address assigned to you by your ISP (Static IP

Page 223 - Internet

ZyWALL 10 Internet Security GatewayInternet Access 3-11Figure 3-7 Internet Access Setup (PPTP)The following table contains instructions about the new

Page 224

ZyWALL 10 Internet Security Gatewayvi CE

Page 225

ZyWALL 10 Internet Security Gateway3-12 Internet Accessknown as dynamic service selection. This enables the service provider to easily create and offe

Page 226 - Content Filtering

ZyWALL 10 Internet Security GatewayInternet Access 3-133.4 Basic Setup CompleteWell done! You have successfully connected, installed and set up your

Page 227 - Figure 20-1 Categories Screen

Advanced ApplicationsIIPart II: Advanced ApplicationsChapters 4 — 6 describe advanced applications including Remote Node Setup, IP Static routesand NA

Page 228 - 20.2 Update List

ZyWALL 10 Internet Security GatewayRemote Node Setup 4-1Chapter 4Remote Node SetupThis chapter shows you how to configure a remote node.A remote node

Page 229 - 20.3 Exempting Computers

ZyWALL 10 Internet Security Gateway4-2 Remote Node SetupTable 4-1 Fields in Menu 11.1FIELD DESCRIPTION EXAMPLERem Node Name Enter a descriptive name f

Page 230 - 20.4 Customizing

ZyWALL 10 Internet Security GatewayRemote Node Setup 4-3Once you have configured the Remote Node Profile Menu, press [ENTER] to return to menu 11.Pres

Page 231 - 20.5 Keywords

ZyWALL 10 Internet Security Gateway4-4 Remote Node SetupDo not specify a nailed-up connection unless your telephone company offers flat-rate service o

Page 232 - 20.6 Log Records

ZyWALL 10 Internet Security GatewayRemote Node Setup 4-5Figure 4-3 Menu 11.1 — Remote Node Profile for PPTP EncapsulationThe next table shows how to c

Page 233 - Part V:

ZyWALL 10 Internet Security Gateway4-6 Remote Node Setup4.2 Editing TCP/IP Options (with Ethernet Encapsulation)Move the cursor to the Edit IP field

Page 234

ZyWALL 10 Internet Security GatewayRemote Node Setup 4-7FIELD DESCRIPTION EXAMPLEPrivate This field is valid only for PPTP/PPPoE encapsulation. Thispa

Page 235 - Troubleshooting

ZyWALL 10 Internet Security GatewayZyXEL Limited Warranty viiZyXEL Limited WarrantyZyXEL warrants to the original end user (purchaser) that this produ

Page 236 - 21-2 Troubleshooting

ZyWALL 10 Internet Security Gateway4-8 Remote Node SetupFigure 4-5 Menu 11.3 — Remote Node Network Layer OptionsThe next table gives you instructions

Page 237 - Troubleshooting 21-3

ZyWALL 10 Internet Security GatewayRemote Node Setup 4-9FIELD DESCRIPTION EXAMPLEnumber.Private This parameter determines if the ZyWALL will include t

Page 238

ZyWALL 10 Internet Security Gateway4-10 Remote Node SetupFigure 4-6 Menu 11.5 — Remote Node Filter (Ethernet Encapsulation)Figure 4-7 Menu 11.5 — Remo

Page 239 - Appendix A

ZyWALL 10 Internet Security GatewayIP Static Route Setup 5-1Chapter 5IP Static Route SetupThis chapter shows you how to configure static routes with y

Page 240

ZyWALL 10 Internet Security Gateway5-2 IP Static Route Setup5.1 IP Static Route SetupYou configure IP static routes in menu 12. 1, by selecting one o

Page 241 - Appendix B

ZyWALL 10 Internet Security GatewayIP Static Route Setup 5-3Table 5-1 IP Static Route Menu FieldsFIELD DESCRIPTIONRoute # This is the index number of

Page 243 - Hardware Specifications

ZyWALL 10 Internet Security GatewayNAT 6-1Chapter 6Network Address Translation (NAT)This chapter discusses how to configure NAT on the ZyWALL.6.1 Intr

Page 244 - Important Safety Instructions

ZyWALL 10 Internet Security Gateway6-2 NATThe global IP addresses for the inside hosts can be either static or dynamically assigned by the ISP. Inaddi

Page 245 - Firewall CLI Commands

ZyWALL 10 Internet Security GatewayNAT 6-36.1.4 NAT Mapping TypesNAT supports five types of IP/port mapping. They are:1. One to One: In One-to-One

Page 246 - H CLI Commands

ZyWALL 10 Internet Security Gatewayviii Customer SupportCustomer SupportWhen you contact your customer support representative please have the followin

Page 247 - CLI Commands I

ZyWALL 10 Internet Security Gateway6-4 NATTYPE IP MAPPING SMT ABBREVIATIONServer Server 1 IP!" IGA1Server 2 IP!" IGA1Server 3 IP!" IGA1

Page 248 - J CLI Commands

ZyWALL 10 Internet Security GatewayNAT 6-5Figure 6-2 NAT Application6.2 SMT Menus6.2.1 Applying NAT in the SMT MenusYou apply NAT via menus 4 or 11.3

Page 249 - CLI Commands K

ZyWALL 10 Internet Security Gateway6-6 NATFigure 6-3 Menu 4 — Applying NAT for Internet AccessThe following figure shows how you apply NAT to the remo

Page 250 - Power Adapter Specifications

ZyWALL 10 Internet Security GatewayNAT 6-7Table 6-3 Applying NAT in Menus 4 & 11.3FIELD OPTIONS DESCRIPTIONFull FeatureWhen you select this option

Page 251

ZyWALL 10 Internet Security Gateway6-8 NATEnter 1 to bring up Menu 15.1 — Address Mapping Sets.Figure 6-6 Menu 15.1 — Address Mapping Sets1. NAT_SET i

Page 252 - Glossary of Terms

ZyWALL 10 Internet Security GatewayNAT 6-9Table 6-4 SUA Address Mapping RulesFIELD DESCRIPTION EXAMPLESet Name This is the name of the set you selecte

Page 253 - Glossary of Terms O

ZyWALL 10 Internet Security Gateway6-10 NATFigure 6-8 Menu 15.1.1 — First SetThe Type, Local and Global Start/End IPs are configured in menu 15.1.1.1

Page 254 - P Glossary of Terms

ZyWALL 10 Internet Security GatewayNAT 6-11Table 6-5 Fields in Menu 15.1.1FIELD DESCRIPTION EXAMPLESet Name Enter a name for this set of rules. This i

Page 255 - Glossary of Terms Q

ZyWALL 10 Internet Security Gateway6-12 NATThe following table describes the fields in this screen.Table 6-6 Menu 15.1.1.1 — Configuring an Individual

Page 256 - R Glossary of Terms

ZyWALL 10 Internet Security GatewayNAT 6-136.3.1 Multiple Servers behind NATIf you wish, you can make inside servers for different services, e.g., we

Page 257 - Glossary of Terms S

ZyWALL 10 Internet Security GatewayTable of Contents ixTable of ContentsCopyright...

Page 258 - T Glossary of Terms

ZyWALL 10 Internet Security Gateway6-14 NATStep 4. Press [ENTER] at the “Press ENTER to confirm …” prompt to save your configuration afteryou define

Page 259 - Glossary of Terms U

ZyWALL 10 Internet Security GatewayNAT 6-156.4 Examples6.4.1 Internet Access OnlyIn the following Internet access example, you only need one rule wher

Page 260 - V Glossary of Terms

ZyWALL 10 Internet Security Gateway6-16 NATthe Network Address Translation field in menus 4 and 11.3 is specifically pre-configured to handle thiscase

Page 261 - Glossary of Terms W

ZyWALL 10 Internet Security GatewayNAT 6-176.4.3 Example 3: General CaseIn this example, there are 3 IGAs from our ISP. There are many departments bu

Page 262

ZyWALL 10 Internet Security Gateway6-18 NATStep 3. Enter 1 to configure the Address Mapping Sets.Step 4. Enter 1 to begin configuring this new set.

Page 263

ZyWALL 10 Internet Security GatewayNAT 6-19When you have configured all four rules, Menu 15.1.1 should look as follows.Figure 6-19 Example 3: Final Me

Page 264

ZyWALL 10 Internet Security Gateway6-20 NAT6.4.4 Example 4: NAT Unfriendly Application ProgramsSome applications do not support NAT Mapping using TCP

Page 265 - Index AA

ZyWALL 10 Internet Security GatewayNAT 6-21Figure 6-22 Example 4: Menu 15.1.1.1 — Address Mapping RuleAfter you’ve configured your rule, you should be

Page 266 - BB Index

Advanced ManagementIIIPart III: Advanced ManagementChapters 7 — 12 provides information on ZyWALL Filtering, SNMP Configuration, SystemInformation and

Commentaires sur ces manuels

Pas de commentaire