Zyxel ZyWALL 1100 [367/829] Configuring the security policy control screen

Zyxel ZyWALL 110 [367/829] Configuring the security policy control screen
Chapter 21 Security Policy
ZyWALL/USG Series User’s Guide
367
By putting LAN 1 and the alternate gateway (A in the figure) in different subnets, all returning
network traffic must pass through the ZyWALL/USG to the LAN. The following steps and figure
describe such a scenario.
1 A computer on the LAN1 initiates a connection by sending a SYN packet to a receiving server on the
WAN.
2 The ZyWALL/USG reroutes the packet to gateway A, which is in Subnet 2.
3 The reply from the WAN goes to the ZyWALL/USG.
4 The ZyWALL/USG then sends it to the computer on the LAN1 in Subnet 1.
Figure 246 Using Virtual Interfaces to Avoid Asymmetrical Routes
21.4.1 Configuring the Security Policy Control Screen
Click Configuration > Security Policy > Policy Control to open the Security Policy screen.
Use this screen to enable or disable the Security Policy and asymmetrical routes, set a maximum
number of sessions per host, and display the configured Security Policies. Specify from which zone
packets come and to which zone packets travel to display only the policies specific to the selected
direction. Note the following.
Besides configuring the Security Policy, you also need to configure NAT rules to allow computers
on the WAN to access LAN devices.
The ZyWALL/USG applies NAT (Destination NAT) settings before applying the Security Policies. So
for example, if you configure a NAT entry that sends WAN traffic to a LAN IP address, when you
configure a corresponding Security Policy to allow the traffic, you need to set the LAN IP address
as the destination.
The ordering of your policies is very important as policies are applied in sequence.
The following screen shows the Security Policy summary screen.

Содержание

Похожие устройства