Gebruiksaanwijzing /service van het product ZYWALL10 van de fabrikant ZyXEL Communications
Ga naar pagina of 267
ZyW ALL 10 Internet Secu rity G ateway User’s Guide Version 3.24 April 2001.
ZyW ALL 10 Internet Security G ateway ii Copyright Copyright Copyright © 2001 by ZyXEL Communications Corporation. The content s of this publ ication may not be reprodu ced in any part or as a wh ole.
ZyW ALL 10 Internet Security G ateway FCC iii Federal Communications Commission (FCC) Interference Statement This device co mplies with Pa rt 1 5 of FCC rules. Operation is subj ect to the following two conditions: This device may not cause harmful in terference.
ZyW ALL 10 Internet Security G ateway iv Canadian Us ers Information for Canadian Users The Industry Canad a label iden tif ies certifi ed equi pme nt. T his cer tifi cat ion mea ns that the equipment meet s certain tele communicatio ns netw ork protectiv e, operation, and safety req uirements.
ZyW ALL 10 Internet Security G ateway Declaratio n of Conf ormit y v Declaration of Confor mit y We, the Manufacturer/Importer, ZyXEL Communications Cor p .
ZyW ALL 10 Internet Security G ateway vi CE.
ZyW ALL 10 Internet Security G ateway ZyXEL Lim ited W arrant y vii ZyXEL Limited W arranty ZyXE L warrants to the origi nal end us er (purchaser) that this pro duct is free fro m any defe cts in mat erials or workmans hip for a peri od of up to tw o years from t he date of p urchase.
ZyW ALL 10 Internet Security G ateway viii Custom er Support Customer Support When you contact your customer support representative please hav e the following informat ion read y: ♦ ZyWALL Model an d serial num ber. ♦ Information in Menu 24.2.1 — System Inform ation .
ZyW ALL 10 Internet Security G ateway Table of Contents ix T able of Contents Copyright ...................................................................................................................... ............................... ii Federal Communications Commission (FCC) Interfer ence Statement.
ZyW ALL 10 Internet Security G ateway x Table of Contents 2.7 General Setup ............................................................................................................... ............... 2-9 2.7.1 Dynamic DNS .........................
ZyW ALL 10 Internet Security G ateway Table of Contents xi 5.1 IP Static Route Setup ....................................................................................................... ........... 5-2 Chapter 6 Network Addr ess T ranslation (NA T ) .
ZyW ALL 10 Internet Security G ateway xii Table of Cont ents 7.6.2 Remote Node Filters....................................................................................................... ...7-17 Chapter 8 SNMP Configuration.........................
ZyW ALL 10 Internet Security G ateway Table of Contents xiii 11.2 Call Control S upport ....................................................................................................... ......... 11-2 11.2.1 Budget Management....................
ZyW ALL 10 Internet Security G ateway xiv Table of Cont ents 14.1 SMT Menus.................................................................................................................. .............14-1 14.1.1 View Firewall L og .................
ZyW ALL 10 Internet Security G ateway Table of Contents xv 17.1 Introduction ............................................................................................................... ............... 17-1 17.2 Creating/Editing A Cu stom Port ....
ZyW ALL 10 Internet Security G ateway xvi Table of Cont ents Appendix E Fire wall CLI Co mmands ............................................................................................... ....... G Appendix F Power Adapter Specifications .........
ZyW ALL 10 Internet Security G ateway List of F igures xvii List of Figures Figure 1-1 Secu re Internet Access via Cable .................................................................................... ............. 1-4 Figure 1-2 Secu re Internet Access via DSL .
ZyW ALL 10 Internet Security G ateway xviii List of Figures Figure 4-4 Men u 1 1.3 — Remote Node Network L ayer Options ................................................................... 4-6 Figure 4-5 Men u 1 1.3 — Remote Node Network L ayer Options .
ZyW ALL 10 Internet Security G ateway List of F igures xix Figure 6-21 NA T Example 4 ...................................................................................................... .................. 6-20 Figure 6-22 Ex ample 4: Menu 15.1.1.1 — Addres s Mapping Ru le .
ZyW ALL 10 Internet Security G ateway xx List of F igures Figure 9-8 Men u 24.3.2 — System Maintenance — UNIX Syslog................................................................ 9-6 Figure 9-9 C all-T riggering Packet Example ..................
ZyW ALL 10 Internet Security G ateway List of F igures xxi Figure 12-1 T eln et Configuration on a TCP/IP Network ........................................................................... .. 12-1 Figure 13-1 Zy W ALL Firewall Application ...........
ZyW ALL 10 Internet Security G ateway xxii List of Fig ures Figure 19-2 Ex ample 1: E-m ail Screen ........................................................................................... .............. 19-3 Figure 19-3 Ex ample 1: Config uring a Rule .
ZyW ALL 10 Internet Security G ateway List of T ables xxiii List of T ables T a ble 2-1 LED f unctions ........................................................................................................ ........................ 2-1 T a ble 2-2 Main Men u Commands .
ZyW ALL 10 Internet Securit y Gatewa y xxiv List of T ables T a ble 7-2 Ru le Abbreviations Used .............................................................................................. ..................7-6 T a ble 7-3 TCP/I P Filter Rule Menu Fields .
ZyW ALL 10 Internet Security G ateway List of T ables xxv T a ble 17-1 Cu stom Ports ........................................................................................................ ...................... 17-2 T a ble 17-2 Creatin g/Editing A Custom Port .
.
ZyW ALL 10 Internet Security G ateway Prefac e xxvi i Preface A bout Y our Router Congratu lations on y our purchase of the ZyWALL 10 Int ernet Security Gateway. Don’t forget to register your ZyWALL (fast, easy online registration at www .zyxel.com ) for free future product updates and information.
ZyW ALL 10 Internet Securit y Gatewa y xxviii Preface Regardless of your particular application, it is i mportant that you follow the steps outli ned in Chapters 1 and 2 to connect y our ZyWALL to your LAN. You can then refer to th e appropriate chapters of th e manual, dep ending o n your app licat i o ns.
Getting Starte d I Part I: Getti ng Starte d Chapters 1— 3 are str uctured as a step-b y-step gu ide to hel p you connec t, inst all and set up your Zy WA L L to operate on your network and acces s the Interne t.
.
ZyWALL 10 Internet Sec urity G ateway Getting to Know Y our Z y WALL 1-1 Chapter 1 Getting to Know Your ZyWALL This chapt er introd uces the main feat ures and ap plicatio ns of the ZyW ALL.
ZyWALL 10 Internet Sec urity Gate way 1-2 Getting to Know Y our Z y WALL PPTP En capsul ation Point- to-Point Tunneling Protocol ( PPTP) is a ne twork prot ocol that en ables secure transf er of data f rom a remote client to a private s erver, creating a Virtual Private Network (VPN) using a TCP/IP-based netw ork.
ZyWALL 10 Internet Sec urity G ateway Getting to Know Y our Z y WALL 1-3 Full Network Management This feature allows you to access the SMT (Sys tem Management Terminal) through the console port or teln et connection. RoadRunner Suppor t In addition to st andard cable modem services, the ZyWALL supports Tim e Warner’s RoadRunner Serv ice.
ZyWALL 10 Internet Sec urity Gate way 1-4 Getting to Know Y our Z y W ALL Figure 1-1 Secure In ternet Acc ess v ia Cable Figure 1-2 Secure In ternet Ac cess v ia DSL You can als o use your xDSL modem in the bridg e mode for always -on Internet access and h igh-speed data transfer.
ZyWALL 10 Internet Sec urity G ateway Hard ware Inst a lla ti on & Initia l Se tup 2-1 Chapter 2 Hardware Installation & Initial Setup This chapt er explai ns the LEDs and ports as well as how to connec t the har dware and p erform the initia l set up.
ZyWALL 10 Internet Sec urity Gate way 2-2 Hardware Insta lla ti on & Initia l Se tup LEDS FUNCTION INDICATOR STATUS ACTI VE DESCRIPTION Off The W AN Link is not ready, or ha s failed. On The W AN Link is OK. WAN W AN Green Flashing The 10M WAN link i s sending/r eceiving packets.
ZyWALL 10 Internet Sec urity G ateway Hard ware Inst a lla ti on & Initia l Se tup 2-3 console port of the Zy WALL and the other en d (choice of 9- pin or 25-pin , depending on your computer) end to a seri al port (COM1, COM2 or other COM port) of y our workstation.
ZyWALL 10 Internet Sec urity Gate way 2-4 Hardware Insta lla ti on & Initia l Se tup 3. A cable/xDSL m odem and an ISP account. After the ZyWALL is properly set up, you can make future changes to t he configuration through telnet connections.
ZyWALL 10 Internet Sec urity G ateway Hard ware Inst a lla ti on & Initia l Se tup 2-5 Several operations that you should be familiar with before you attempt to modify the configuration are listed in the table belo w.
ZyWALL 10 Internet Sec urity Gate way 2-6 Hardware Insta lla ti on & Initia l Se tup 2.5.1 Main Menu After you enter the password, the SMT displa ys the Z yWAL L 1 0 Mai n Me nu , as sho wn next. Figure 2-5 ZyWALL 10 Main Menu Copyright (c) 1994 - 2001 ZyXEL Communications Corp.
ZyWALL 10 Internet Sec urity G ateway Hard ware Inst a lla ti on & Initia l Se tup 2-7 2.5.2 Syst em Management T erminal Interf ace Summary Table 2- 3 Main M enu Summary NO. MENU TITLE FUNCTION 1 General Setup Use this menu to set up routing/br idg ing and general infor mati on.
ZyWALL 10 Internet Sec urity Gate way 2-8 Hardware Insta lla ti on & Initia l Se tup 2.5.3 SMT Menus at a Glance Figure 2-6 SM T Menus at a Glance.
ZyWALL 10 Internet Sec urity G ateway Hard ware Inst a lla ti on & Initia l Se tup 2-9 2.6 Changing the System Pass word The firs t thing y ou should do i s chang e the default system passw ord by following the steps shown next . Step 1. Enter 23 in the main menu to ope n M enu 23 - Syst em Passw ord as shown belo w.
ZyWALL 10 Internet Sec urity Gate way 2-10 Hardware Inst a lla ti on & Initia l Se tup The Domain Name entry is what is propagated to the DHCP client s on the LAN. If you leave this field blank, the d o main name o bta i ned b y DHCP fro m the ISP is used .
ZyWALL 10 Internet Sec urity G ateway Hard ware Inst a lla ti on & Initia l Se tup 2-1 1 Table 2-4 General Setup Menu Field FIELD DESCRIPTION EXAMPLE System Na me Choose a des criptive na me for ident ification purpo ses. It is recommende d you enter y our comput er’s “Computer name” in th is field.
ZyWALL 10 Internet Sec urity Gate way 2-12 Hardware Inst a lla ti on & Initia l Se tup Table 2-5 Configure Dynamic DNS Menu Fields FIELD DESCRIPTION EXAMPLE Service Provider Enter the na me of your Dy namic DN S client. www .dyndns.org Active Press [SPACE BAR] to cycle between Yes or No .
ZyWALL 10 Internet Sec urity G ateway Hard ware Inst a lla ti on & Initia l Se tup 2-1 3 Figure 2-10 Menu 2 — W A N Setup The MAC address field allows users to configu re the WAN port's MAC address by eith er using the factory default or clon ing the MAC address from a com puter on your LAN.
ZyWALL 10 Internet Sec urity Gate way 2-14 Hardware Inst a lla ti on & Initia l Se tup Figure 2-11 Menu 3 — L A N Setup 2.9.1 LAN Port Filter Setup This menu allows you to specif y the filter sets that you wish to apply to the LAN traffic.
ZyWALL 10 Internet Sec urity G ateway Internet Acc ess 3-1 Chapter 3 Internet Access This chapt er shows y ou how to c onfigure t he LAN as well as the WAN of y our ZyW ALL for Intern et access.
ZyWALL 10 Internet Sec urity Gate way 3-2 Internet Acc ess Example of netw ork properti es for L AN servers wit h fixed IP add resses: Choose an IP address: 192.168.1.2 - 192.168.1.32 ; 192.168 .1.65 - 192.16 8.1.254. Subnet mask: 255.255.255.0 Gateway (or default route): 192.
ZyWALL 10 Internet Sec urity G ateway Internet Acc ess 3-3 Internet address es for your local netw orks. On the other hand, if y ou are part of a much larger org anization, you sh ould consult your network administrator f or the appropriate I P address es.
ZyWALL 10 Internet Sec urity Gate way 3-4 Internet Acc ess WAN int erfaces using menus 3.2 (LA N) and 11.3 (WA N). Select None to disable IP Multicasting on these interfaces. 3.1.7 IP A lias IP Alias allows you to partition a physical net work into different logical networks over the same Ethernet interface.
ZyWALL 10 Internet Sec urity G ateway Internet Acc ess 3-5 Figure 3-3 Menu 3 — LAN Setup From menu 3, select th e submenu option TCP/IP and DHCP Set up and press [ ENTER ]. T he screen n ow display s M enu 3.2 — TCP/IP a nd DHCP Ethernet Setup , as sh own.
ZyWALL 10 Internet Sec urity Gate way 3-6 Internet Acc ess Table 3-1 DHCP Ethernet Setup Menu Fields FIELD DESCRIPTION EXAMPLE DHCP This field enables /disables the DHCP server. If set to Server , y our Zy W ALL w ill act as a DHCP server. If set to None , th e DHCP server will be disabled.
ZyWALL 10 Internet Sec urity G ateway Internet Acc ess 3-7 FIELD DESCRIPTION EXAMPLE Multicast IGMP (Internet Gro up Multica st Protocol) is a sess ion-layer proto col used to esta blish me mbership in a Multica st group. T he Zy W ALL supports both IGM P version 1 ( IGMP-v1 ) a nd version 2 ( IG MP-v2 ).
ZyWALL 10 Internet Sec urity Gate way 3-8 Internet Acc ess Use the instructions in the following table to con figure IP Alias p arameters. Table 3-3 IP Alias Setup Menu Fields FIELD DESCRIPTION EXAMPLE IP Alias Choose Yes t o configure the LAN netw ork for the Zy W ALL.
ZyWALL 10 Internet Sec urity G ateway Internet Acc ess 3-9 Figure 3-6 Men u 4 — Internet Access Setup (Eth ernet) The following table describes t his screen. Table 3- 4 Intern et Access Set up M enu Fields FIELD DESCRIPTION ISP’s Name Enter the name of your Intern et Service Provid er, e.
ZyWALL 10 Internet Sec urity Gate way 3-10 Internet Acc ess FIELD DESCRIPTION IP Address Enter the (fix ed) IP address assign ed to you by y our ISP (Static IP A ddress Assignment is select ed in the prev ious fie ld). IP Subnet M ask Enter the subne t mask asso ciated w ith your static IP.
ZyWALL 10 Internet Sec urity G ateway Internet Acc ess 3-1 1 Figure 3- 7 Intern et Access Setup ( PPT P) The follow ing table contai ns instructions about the new fields when y ou choose PPTP in th e Encaps ulation field in M enu 4 .
ZyWALL 10 Internet Sec urity Gate way 3-12 Internet Acc ess known as dynamic service selection. This en ables the service provider to easily create an d offer new IP services f or specific u sers.
ZyWALL 10 Internet Sec urity G ateway Internet Acc ess 3-13 3.4 Basic Setup Complete Well done! You h ave successfully connected, ins talled and set up your Zy W ALL to operate on your n etwork as well as access the Internet.
Advance d App licatio ns II Part II: Advanced Applications Chapters 4 — 6 des cribe adv anced appl ications i ncluding R em ote Node Setup, IP Static routes and NA T .
ZyWALL 10 Internet Sec urity Gate way Remote Node Setup 4-1 Chapter 4 Remote Node Setup This chapt er shows y ou how to c onfigure a remote node. A remote node is required for placing calls to a remote gateway. A rem ote node represents both the remote gate way and the ne t work b ehind it ac r oss a W AN co n necti o n.
ZyWALL 10 Internet Sec urity Gate way 4-2 Rem ote Node Setup Table 4- 1 Fields in M enu 11.1 FIELD DESCRIPTION EXAMPLE Rem Node N ame Enter a descri ptive name for the remot e node. Thi s field can be up to eight characters . LAoffice Active Press [SPACE BAR] to select Yes (activate remote node) or No (deactivate r emote node).
ZyWALL 10 Internet Sec urity Gate way Remote Node Setup 4-3 Once you h ave configured the Remot e Node Profile M enu, press [ENTER] to retur n to menu 11. Press [ENTER] at the message “Pre ss ENTER to Conf irm...” to sav e your configurat ion, or pres s [ESC] at any time to cancel .
ZyWALL 10 Internet Sec urity Gate way 4-4 Rem ote Node Setup Do not specify a nailed-u p connection unless your telephone company off ers flat-rate service or you need a constant conn ection and the cost is of no concern. The follow ing table descri bes the fields n ot already described in Table 4-1 .
ZyWALL 10 Internet Sec urity Gate way Remote Node Setup 4-5 Figure 4-3 Menu 11.1 — Remote Node Profile for PPTP Encapsulation The next table shows how to configu re fields in m enu 11.
ZyWALL 10 Internet Sec urity Gate way 4-6 Rem ote Node Setup 4.2 Editi ng TCP/IP Options (with Ethernet Encapsulati on) Move the cursor to the Edit IP field in menu 11.1, then press th e [SPACE BA R] to toggle and set the value to Yes . Press [ENTER] to open Menu 11.
ZyWALL 10 Internet Sec urity Gate way Remote Node Setup 4-7 FIELD DESCRIPTION EXAMPLE Private This field i s valid only for PPTP/PPPoE encapsul ation. This parameter deter mines if t he ZyW ALL will in clude the ro ute to this remote no de in its RIP br oadcasts.
ZyWALL 10 Internet Sec urity Gate way 4-8 Rem ote Node Setup Figure 4-5 Menu 11.3 — Remote Node Network Layer Options The next tab le gi ve s you i nstr uctio ns abo ut con figur i ng r e mote no de net wor k la yer o ptio ns.
ZyWALL 10 Internet Sec urity Gate way Remote Node Setup 4-9 FIELD DESCRIPTION EXAMPLE number. Private This paramet er determine s if the Zy W ALL will i nclude the r oute to this remote no de in its RIP br oadcasts. If set t o Yes , this ro ute is kept private and n ot include d in RIP broadc ast.
ZyWALL 10 Internet Sec urity Gate way 4-10 Rem ote Node Setup Figure 4-6 Menu 11.5 — Remote Node Filter (Ethernet Encapsulation) Figure 4-7 Menu 11.5 — Remote Node Filter (PPPoE or PPTP Encapsulation) Menu 11.
ZyWALL 10 Internet Sec urity Gate way IP Static Route Setu p 5-1 Chapter 5 IP Static Route Setup This chapt er shows y ou how to c onfigure s tatic rou tes with yo ur ZyW ALL. Static routes tell the ZyWALL routing information that it cannot lear n automatically through other means.
ZyWALL 10 Internet Sec urity Gate way 5-2 IP Stat ic Route Setup 5.1 IP Static Route S etup You configure IP static routes in menu 12. 1, by selecting one of the IP static ro utes a s shown b elo w.
ZyWALL 10 Internet Sec urity Gate way IP Static Route Setu p 5-3 Table 5- 1 IP Stati c Route M enu Fields FIELD DESCRIPTION Route # This is the ind ex number of the static route that y ou chose in m enu 12. Route Name Enter a descri ptive name for this rout e.
.
ZyWALL 10 Internet Sec urity Gate way NA T 6-1 Chapter 6 Network Address Translation (NAT) This chapt er disc usses how to c onfigure NAT on t he ZyW ALL. 6.1 Introducti on NAT (Netw ork Address Transl ation - NAT, RFC 1631) is t he transl ation of the IP addres s of a host in a packet, e.
ZyWALL 10 Internet Sec urity Gate way 6-2 NA T The global IP addresses for the inside hos ts can be either static or dynamically assi gned by the ISP. In addition, you can designate servers, e.g., a web server and a telnet server, on your local network and make them accessi ble to the outside world.
ZyWALL 10 Internet Sec urity Gate way NA T 6-3 6.1.4 NA T Mapping T ypes NAT su pports five types of IP/port mappi ng. They are: 1. One to One: In One-to-On e mode, the ZyWALL maps one local IP address to on e global IP addres s. 2. Many t o One: In Many-to-One m ode, the ZyWALL maps mu ltiple local IP addres ses to one g lobal IP address.
ZyWALL 10 Internet Sec urity Gate way 6-4 NA T TYPE IP MAPPING SMT ABBREVIATION Server Server 1 IP !" IGA1 Server 2 IP !" IGA1 Server 3 IP !" IGA1 Server 6.
ZyWALL 10 Internet Sec urity Gate way NA T 6-5 Figure 6-2 NAT Application 6.2 SM T Menus 6.2.1 A ppl ying NA T in the SMT Menus You apply NAT via menus 4 or 11 .3 as display ed next. The next f igure shows you how to apply NAT for Internet access in menu 4.
ZyWALL 10 Internet Sec urity Gate way 6-6 NA T Figure 6-3 Men u 4 — Applying NAT fo r Internet Access The follow ing figure sh ows how you apply NAT to the remote n ode in menu 11.
ZyWALL 10 Internet Sec urity Gate way NA T 6-7 Table 6-3 Applying NAT in Menus 4 & 11.3 FIELD OPTIONS DESCRIPTION Full Feature When you se lect this o ption the SMT will use Address M apping Set 1 (me nu 15.1 - see section 6.2.3 for further dis cu ssion).
ZyWALL 10 Internet Sec urity Gate way 6-8 NA T Enter 1 to bring up Menu 15. 1 — Address Mapping Sets . Figure 6-6 Menu 15.1 — Address Mapping Sets 1. NAT _SET is a se t name tha t was cr e ate d as an exa mple . Info rm a tio n abo ut cre a ti ng your own addre s s map pin g se ts is provide d la te r in the cha pter .
ZyWALL 10 Internet Sec urity Gate way NA T 6-9 Table 6- 4 SUA Add ress M apping Rules FIELD DESCRIPTION EXAMPLE Set Name This is the name of the set you sele cted in men u 15.1 or ent er the name of a new set y ou want to create. SUA Idx This is the index or rule number .
ZyWALL 10 Internet Sec urity Gate way 6-10 NA T Figure 6-8 Men u 15.1.1 — Fir st Set The Ty pe, Local a nd Glob al Start/ End IPs are config ured i n menu 1 5.1.1.1 (de s cribed later) a nd the v alues are displa yed her e. Ordering Y our Rules Ordering y our rules is important because the Zy WALL applies the rules in the order that you specify.
ZyWALL 10 Internet Sec urity Gate way NA T 6-1 1 Table 6- 5 Fields in M enu 15.1.1 FIELD DESCRIPTION EXAMPLE Set Name Enter a name for this set of rule s. This i s a required field. Please note that if this fi eld is left blank, the entire set will be del eted.
ZyWALL 10 Internet Sec urity Gate way 6-12 NA T The following table describes the fields in this screen. Table 6-6 Menu 15.1.1.1 — Configuring an Individual Rule FIELD DESCRIPTION EXAMPLE Type Press the [SPACE BAR] to toggl e through a total of five types.
ZyWALL 10 Internet Sec urity Gate way NA T 6-13 6.3.1 Multiple Serv ers behind NA T If you w ish, you can make inside s ervers for different serv ices, e.g., web or FTP, visible to the ou tside users, even though NAT m akes your whole inside n etwork appear as a si ngle machine t o the outside world.
ZyWALL 10 Internet Sec urity Gate way 6-14 NA T Step 4. P ress [ENTER] at the “Press ENTER to confirm …” pro mpt to save your configuration after you define all the s ervers or press [ESC] at any time to cancel. If you’ re usin g Ether net Enca psulatio n the SMT does no t allow you to c hange the port 1026 e ntry.
ZyWALL 10 Internet Sec urity Gate way NA T 6-15 6.4 Examples 6.4.1 Internet A ccess Only In the following In ternet access example, you only need one ru le where all your ILAs (Inside L ocal addresses ) map to one dy namic IGA (In side Global A ddress) assi gned by y our ISP.
ZyWALL 10 Internet Sec urity Gate way 6-16 NA T the Network A ddress Trans lation field i n menus 4 and 11.3 is specifically pre-configured to handle th is case.
ZyWALL 10 Internet Sec urity Gate way NA T 6-17 6.4.3 Example 3: G eneral Case In this example, th ere are 3 IGAs from ou r ISP. T here are many departm ents but two have their own FT P server. All departm ents share the same rout er. The example will reserve one IGA for each departm ent with an FTP server and the oth er IGA is used by all.
ZyWALL 10 Internet Sec urity Gate way 6-18 NA T Step 3. Enter 1 to co nfigure the Address Mapping Sets. Step 4. Enter 1 to b egin configu ring this new set. Enter a Set Na me, choose the Edit Ac t i o n and t hen enter 1 for the Select Rule field. Press [ENTER] to confirm .
ZyWALL 10 Internet Sec urity Gate way NA T 6-19 When y ou have configu red all four rul es, Menu 15.1.1 shou ld look as follows. Figure 6-1 9 Exampl e 3: Final M enu 15.1.1 Now conf igure the IGA3 to m ap to our we b server and ma il server on the LA N.
ZyWALL 10 Internet Sec urity Gate way 6-20 NA T 6.4.4 Example 4: NA T Unfriendly Application Programs Some appli cations do n ot support NA T Mapping usi ng TCP or UDP port address tran slation.
ZyWALL 10 Internet Sec urity Gate way NA T 6-21 Figure 6-2 2 Exampl e 4: Menu 15.1.1.1 — Address M apping Rule After you’ve con fi gure d your rule, you s ho uld b e able to che c k the se t ting s i n me nu 1 5.1 .1 a s sho wn ne xt. Figure 6-2 3 Exampl e 4: Menu 15.
Advance d Managem ent III Part III: Advanced Manage ment Chapters 7 — 12 prov ides inf orm ation on ZyWALL Filter ing, SNM P Configur ation, S ystem Inform ation and D iagnosis , Transferring Files , System Mainte nance and T elnet.
.
ZyWALL 10 Internet Sec urity Gate way Filters 7-1 Chapter 7 Filter Configuration This chapt er shows y ou how to c reate a nd apply fi lters. 7.1 About Filtering Your Zy W ALL uses filters to decide whether to allow pass age of a data packet and/or to m ake a call.
ZyWALL 10 Internet Sec urity Gate way 7-2 Filters 7.1.1 The Filter Structur e of the Zy W ALL A filter set consists of one or more filter rules. Usually, you would group related rules, e.g., all the rules for NetBIOS, into a single set and give it a descripti ve name.
ZyWALL 10 Internet Sec urity Gate way Filters 7-3 Start Fetch First Filter Set Fetch First Filter Rule Active? Execute Filter Rule Fetch Next Filter Rule Next filter Rule Available? Fetch Next Filter .
ZyWALL 10 Internet Sec urity Gate way 7-4 Filters 7.2 Configur i ng a Fil ter Set To configu re a filter set, follow the procedure below. For m ore information on menus 21.2 and 21.3, please see Part 4. Step 1. Select option 21. Filter Set Configuration from th e main menu to open m enu 21.
ZyWALL 10 Internet Sec urity Gate way Filters 7-5 Figure 7-6 NetBIOS_W AN Filter Rul es Summa ry Figure 7-7 NetBIOS _L AN Filter Rules Summ ary Figure 7-8 TEL_FTP_WEB_WAN Filter Rules Summary Menu 21.1.1 - Filter Rules Summary # A Type Filter Rules M m n - - ---- -------------------------------------------- --------- - - - 1 Y IP Pr=6, SA=0.
ZyWALL 10 Internet Sec urity Gate way 7-6 Filters 7.2.1 Filter Rules Summary Menu This screen shows the summary of the existing rules in the filter set. The following tables con tain a brief description of the abbrev iations used i n the previous menus.
ZyWALL 10 Internet Sec urity Gate way Filters 7-7 ABB RE VI ATI ON DESCRIPTION GEN Off Offset Len Length Refer to the next section for information on configuring the filter rules. 7.2.2 Configuring a Filter Rule To configure a f ilter rule, type its number in Menu 21.
ZyWALL 10 Internet Sec urity Gate way 7-8 Filters The following table describes ho w to configure your TCP/IP filter rule. Table 7-3 TCP/IP Filter Rule M enu Fields FIELD DESCRIPTION OPTIONS Active Yes activate s the filter r ule and No deactiv at es it.
ZyWALL 10 Internet Sec urity Gate way Filters 7-9 FIELD DESCRIPTION OPTIONS according to the action fields. If More is Yes , then A ction Matc hed and Action Not Matched w ill be N/A . Log Select the loggin g option fro m the follow ing: None – No pac kets will b e logged.
ZyWALL 10 Internet Sec urity Gate way 7-10 Filters The following figure illustrates the logic flo w of an IP filter. Packet into IP Filter Matched Matched Yes Action Matched Action Not Matched More? N.
ZyWALL 10 Internet Sec urity Gate way Filters 7-1 1 7.2.4 Generic Filter Ru le This section shows you ho w to configure a generic filter rule. The purpose of generic rules is to allow you to filter non-IP packets. For IP, it is generally easier to use the IP rules directly.
ZyWALL 10 Internet Sec urity Gate way 7-12 Filters Table 7- 4 Generic Filt er Rule M enu F ields FIELD DESCRIPTION OPTIONS Filter # This is the filter set, f ilter rule co-o rdinates, i.e., 2,3 refer s to the se cond filter set and the thir d rule of that set.
ZyWALL 10 Internet Sec urity Gate way Filters 7-13 7.3 Example Filter Let’s look at an example to block outside users fro m telnetting into the ZyWALL. Please see our included disk for m ore example filters. Figure 7-1 2 Telnet Filter Ex ample Step 1.
ZyWALL 10 Internet Sec urity Gate way 7-14 Filters Figure 7-1 3 Example F ilter — M enu 21.1.1.1 When y ou press [ENTE R] to conf ir m, you will see the following screen.
ZyWALL 10 Internet Sec urity Gate way Filters 7-15 Figure 7-1 4 Example F ilter Rules Summary — M enu 21.1.3 After you’ve created the filter set, you must apply it. Step 1. Enter 11 from the main menu to g o to menu 11. Step 2. Go to the Edit Filter Sets fi eld, press the [SPA CE BAR ] to select Yes and pres s [ENT ER] .
ZyWALL 10 Internet Sec urity Gate way 7-16 Filters the raw packets that appear on the wire. They are applied at th e point when the Zy WALL is receiving and sending the pack ets; i.e. the interface. The interface can be an Ethernet port or any other hardware port.
ZyWALL 10 Internet Sec urity Gate way Filters 7-17 Figure 7-16 Filtering LAN Traffic 7.6.2 Remote Node Filter s Go to menu 11.5 (sho w n below – note that call filter sets are onl y present for PPPoE encapsulation) and enter the number(s) of the filter set(s) as appropriate.
.
ZyWALL 10 Internet Sec urity Gate way SNMP 8-1 Chapter 8 SNMP Configuration This chapt er disc usses SNMP (Simple Network Managemen t Protoco l) for networ k managem ent and monitor ing. 8.1 About SNMP Your Zy WALL supports SNMP ag ent function ality, which allows a manager stat ion to manage and m onitor the ZyWALL through the netw or k.
ZyWALL 10 Internet Sec urity Gate way 8-2 SNMP The following table describes the SNMP co nfiguration parameters. Table 8-1 SNMP Configuration Menu Fields FIELD DESCRIPTION DEFAULT Get Community Enter th e get comm unity, w hich is the pa ssword for the incoming G et- and GetN ext- request s from the mana gement station.
ZyWALL 10 Internet Sec urity Gate way System Inform ation & Diagn osis 9-1 Chapter 9 System Information & Diagnosis This chapt er cover s SMT me nus 24.1 t o 24.4. This chapter covers the diagnostic to ols that help you to maintain your Zy W ALL.
ZyWALL 10 Internet Sec urity Gate way 9-2 System Inform ation & Diagn osis Figure 9-2 Men u 24.1 — Syst em Maint enance — Stat us The following table describes the fields present in Menu 24 . 1 - System Ma int enance - Stat us . These fields are READ-ONLY and are m eant to be used for diagn ostic purposes.
ZyWALL 10 Internet Sec urity Gate way System Inform ation & Diagn osis 9-3 FIELD DESCRIPTION IP Address The LAN port IP address. IP Mask The LAN port IP mask. DHCP The LAN p ort DHCP role. WA N Ethernet Address The W AN port Eth ernet addres s. IP Address The W AN port IP addre ss.
ZyWALL 10 Internet Sec urity Gate way 9-4 System Inform ation & Diagn osis 9.2.1 Syst em Information Syste m Info r mati o n gi ves yo u i nfor matio n abo ut your system as sho wn b elo w. More sp ecif icall y, it gi ves you inf ormation on you r routing protocol , Ethernet addres s, IP address, et c.
ZyWALL 10 Internet Sec urity Gate way System Inform ation & Diagn osis 9-5 9.2.2 Console Port Speed You can change th e speed of the console port throu gh Menu 24.2.2 – Con sole Port Speed . You r ZyWALL supports 9600 (defau lt), 19200, 38 400, 57600, and 115200 bps for th e console port.
ZyWALL 10 Internet Sec urity Gate way 9-6 System Inform ation & Diagn osis Figure 9-6 Menu 24.3 — System Maintenance — Log and Trace Examples of ty pical error and information messages are pres ented in the figure below. Figure 9-7 Example s of Erro r and Info rmation Messages 9.
ZyWALL 10 Internet Sec urity Gate way System Inform ation & Diagn osis 9-7 You need to conf igure the UNIX syslog parameters described in th e following table to activate syslog then choose w hat you w ant to log .
ZyWALL 10 Internet Sec urity Gate way 9-8 System Inform ation & Diagn osis 1. CDR CDR Message Format Sdcm dSyslogS end( SYSLOG_CDR, SYSLOG_INFO, String ); String = board xx line xx channel xx, cal.
ZyWALL 10 Internet Sec urity Gate way System Inform ation & Diagn osis 9-9 Mar 03 10:39:43 202.132.155.97 ZyXEL: GEN[fffffffffffnordff0080] }S05>R01mF Mar 03 10:41:29 202.132.155.97 ZyXEL: GEN[00a0c5f502fnord010080] }S05>R01mF Mar 03 10:41:34 202.
ZyWALL 10 Internet Sec urity Gate way 9-10 System Inform ation & Diagn osis 9.3.3 Call-T riggering Packet Call-Triggering Packet display s information about the packet that triggered a dial-out call in an easy readable form at. Equivalent information is available in menu 24.
ZyWALL 10 Internet Sec urity Gate way System Inform ation & Diagn osis 9-1 1 Figure 9-10 Menu 24.4 — System Maintenance — Diagnostic Follow the proced ure b e lo w to get to M enu 24.4 - S ystem Maintenance – Diagnostic. Step 1. Fro m the main menu, s elect option 24 t o open Menu 24 - System Maint enance .
ZyWALL 10 Internet Sec urity Gate way 9-12 System Inform ation & Diagn osis Figure 9-11 W AN & LAN DHCP The follo wing table describes t he diagnostic tests a vailable in menu 24.
ZyWALL 10 Internet Sec urity Gate way Firm ware and Config uration F ile Mai ntenance 10-1 Chapter 10 Firmware and Configuration File Maintenance This chapt er tells you how to back up and res tore your co nfigurat ion file as well as uploa d new firmware an d a new co nfigurat ion file.
ZyWALL 10 Internet Sec urity Gate way 10-2 Firm ware and Conf iguration F ile Ma intenance Table 10-1 Filename Conventions FILE TYPE INTERNA L NAME EXTERNAL NAME DESCRIPTION AT COMMAND Configurati on File Rom-0 *.rom This is the r outer configurat ion filename on the Zy W AL L.
ZyWALL 10 Internet Sec urity Gate way Firm ware and Config uration F ile Mai ntenance 10-3 10.2.1 Example: Backup Configurat ion Using Hy perT erminal Thi s se ctio n c onta ins exa mpl e s of ba c kup c onfi gurati o n, r estor e co nfi gur a tion a nd upl oad fi rmwar e usi ng the Hy perTerminal program .
ZyWALL 10 Internet Sec urity Gate way 10-4 Firm ware and Conf iguration F ile Ma intenance 10.3 Restore Configuration Menu 2 4.6 -- System Maint e na nce - Restore Configuration allows you to restore the configuratio n via the console port.
ZyWALL 10 Internet Sec urity Gate way Firm ware and Config uration F ile Mai ntenance 10-5 Figure 10- 8 Telnet int o Men u 24.6 Restore Con figuratio n 10.4 Upload Firmware Menu 2 4.7 -- System Maint e na nce - Upload Firmware allows y ou to upgrade the firmware and the configuration file via th e console port.
ZyWALL 10 Internet Sec urity Gate way 10-6 Firm ware and Conf iguration F ile Ma intenance Step 4. After successful firmware u pload, enter atgo to restart the ZyWALL. Figure 10- 10 Menu 24.7.1 — S ystem Main tenance — Uplo ad Route r Firmware 10.
ZyWALL 10 Internet Sec urity Gate way Firm ware and Config uration F ile Mai ntenance 10-7 Menu 2 4.6 replac es the curre nt confi guratio n with your cu stomized confi guratio n you backed up pre vio us ly.
ZyWALL 10 Internet Sec urity Gate way 10-8 Firm ware and Conf iguration F ile Ma intenance Step 1. Use telnet from your workst ation to connect to the Zy W ALL and log in. Because TFTP does not have any security checks, the ZyWALL records the IP address of the telnet client and accepts TFTP requests only from this addres s.
ZyWALL 10 Internet Sec urity Gate way Firm ware and Config uration F ile Mai ntenance 10-9 COMMAND DESCRIPTION Remote File This is the filena me on the Zy W AL L. The file name for the firmware is “ ras ” an d for the con figuration f ile, is “ rom-0 ”.
ZyWALL 10 Internet Sec urity Gate way 10-10 Firm ware and Config uration F ile Mai ntenance Figure 10- 13 Telnet in to M enu 24.7.1 You see the following screen when you telnet into menu 24.7.2. Figure 10- 14 Telnet in to M enu 24.7.2 — S ystem M aintenance To transfer the f irmware and the configuration file, follow the se examples: Menu 24.
ZyWALL 10 Internet Sec urity Gate way Firm ware and Config uration F ile Mai ntenance 10-1 1 10.6.1 Using the FTP command from the DOS Prompt Step 1. La unc h t he FT P cl i ent on your wor kstat i o n. Step 2. Type open and t he IP address of your ZyWALL.
ZyWALL 10 Internet Sec urity Gate way 10-12 Firm ware and Config uration F ile Mai ntenance Table 10- 3 Third Party FT P Client s — Genera l Fields COMMAND DESCRIPTION Host Addres s Enter the ad dress of the host server. Login T ype Anonymous. This is w hen a user I.
ZyWALL 10 Internet Sec urity Gate way System Maintenance & Inf ormation 11 - 1 Chapter 11 System Maintenance & Information This chapt er leads y ou through SMT me nus 24.8 t o 24.11. 11.1 Command Interpreter Mo de The Command Interpreter (C I) is a part of the m ain router fi rmware.
ZyWALL 10 Internet Sec urity Gate way 1 1-2 System Maintenance & Inf ormation 11.2 Call Control Suppor t The ZyWALL provides two call control fun ctions: budget management an d call history. Please note that this menu is only applicable when Encaps ulation is set to PP PoE or PPTP i n m enu 4 or menu 11.
ZyWALL 10 Internet Sec urity Gate way System Maintenance & Inf ormation 11 - 3 The total budget is the time limit on the accu mulated ti me for outgoing calls to a remote node. When this limit is reached, th e call will be dropped and fu rther outgoing calls to that rem ote node will be blocked.
ZyWALL 10 Internet Sec urity Gate way 1 1-4 System Maintenance & Inf ormation Figure 11-5 Call History Table 11- 2 Call Histo ry Fields FIELD DESCRIPTION Phone Number The PPPoE service name s are show n here. Dir This sh ows w hether the call w as inco ming or outgo ing.
ZyWALL 10 Internet Sec urity Gate way System Maintenance & Inf ormation 11 - 5 Select m enu 24 in the main menu to open Menu 24 - Sy stem Maintenance , as sho wn next.
ZyWALL 10 Internet Sec urity Gate way 1 1-6 System Maintenance & Inf ormation Table 11-3 Time and Date Setting Fields FIELD DESCRIPTION Enter the time service pro tocol that your time server sends w hen you turn on the Zy W ALL.
ZyWALL 10 Internet Sec urity Gate way System Maintenance & Inf ormation 11 - 7 11.4 Remote Management Setup Telnet and F TP do not s upport encry ption, so f or very strong security both servi ces should be s hut down. This is done in Menu 24.11 - Rem ote Managem ent Control .
ZyWALL 10 Internet Sec urity Gate way 1 1-8 System Maintenance & Inf ormation 11.5 Boot Commands The BootModul e AT comman ds execute from within t he router’s boot up software, wh en debug mode i s selected before the m ain router firmware (ZyNOS) is started.
ZyWALL 10 Internet Sec urity Gate way System Maintenance & Inf ormation 11 - 9 Figure 11-10 Boot Module Commands ======= Debug Command Listing ======= AT just answer OK ATHE print help ATBAx change baudrate. 1:38.4k, 2:19.2k, 3:9.6k 4:57.6k 5:115.
.
ZyWALL 10 Internet Sec urity Gate way T elnet 12-1 Chapter 12 Telnet Configuration and Capabilities This chapt er cover s the Teln et Conf iguration a nd Capab ilities of the ZyW ALL. 12.1 About T elnet Configurati on Before th e ZyWALL is properly setup for TCP/IP, the only option for con figuri ng it is throug h the console port.
ZyWALL 10 Internet Sec urity Gate way 12-2 T elnet 12.3.2 Syst em Timeout There is a sy stem timeout of 5 minutes (300 secon ds) for eith er the console port or t elnet. Your Zy W ALL will automatically log you out if you do nothin g in this ti meout period, except when it is continuously updating the status in m enu 24.
Firewall and Cont ent Filters IV Part IV: Firewall and Co ntent Filters Chapters 13 — 20 def ine the ter m “ Firewall”, introduce t he Z y W ALL Firewa ll and ZyWALL Web Configura tor , des cribe ho w to create Cus tom Rules and c onfigure c ustom ized ports, ex plain Logs and prov ide Exam ple Fire wall Rules .
.
ZyWALL 10 Internet Sec urity G ateway W hat Is a Firewall? 13-1 Chapter 13 What is a Firewall? This chapt er giv es some bac kground informat ion on F irewalls. Ori gin ally , the t erm fire wall referred to a constru ction technique designed to prev ent the spread of fi re from one room to another.
ZyWALL 10 Internet Securit y Gatewa y 13-2 W hat Is a Firewall? ii. Robust authen tication and logging pre-authenticates application traff ic before it reaches internal hosts and causes it to b e logged more effectively than if it were logged with standard host logging.
ZyWALL 10 Internet Sec urity G ateway W hat Is a Firewall? 13-3 Figure 13-1 ZyWALL Firewall A pplication 13.3 Denial of Serv ice Denials of Service (DoS) attack s are aimed at devices and netw orks with a connection to th e Internet.
ZyWALL 10 Internet Securit y Gatewa y 13-4 W hat Is a Firewall? Some of the m ost co mm on IP ports are: Table 13- 1 Common IP Ports 21 FTP 53 DNS 23 Telnet 80 H TTP 25 S MT P 110 POP3 13.3.2 T y pes of DoS attacks There are four types of DoS attacks: 1.
ZyWALL 10 Internet Sec urity G ateway W hat Is a Firewall? 13-5 Figure 13-2 Three-Way Handshake Under normal circumstances , the application that initiates a session sends a SYN (synchronize) pack et to the receiving s erver.
ZyWALL 10 Internet Securit y Gatewa y 13-6 W hat Is a Firewall? 3. A br ute-force attack, such as a "Smurf" attack, targ ets a feature in the IP specification know n as directed or s ubnet broadcas ting, to qu ickly flood th e target n et work with usel ess data.
ZyWALL 10 Internet Sec urity G ateway W hat Is a Firewall? 13-7 ! Denies all sessions originating fro m the WAN (Intern et) to the LAN (local network). Figure 1 3-5 Stat eful Inspec tion The previous f igure shows the ZyWALL’s default firewall ru les in action as well as demonstrates how stateful inspection works.
ZyWALL 10 Internet Securit y Gatewa y 13-8 W hat Is a Firewall? 6. Later, an inbou nd packet reaches the interf ace. This packet is part of the connection previously established w ith the outbound packet.
ZyWALL 10 Internet Sec urity G ateway W hat Is a Firewall? 13-9 If an initiation packet originates on the LAN, this means that so meone i s tr ying to make a connection from the LAN to the Intern et. Assuming that this is an acceptable part of the security policy (as is the case with the default policy ), the connection will be allowed.
ZyWALL 10 Internet Securit y Gatewa y 13-10 W hat Is a Firewall? 2. Think about access con trol before you connect a console port t o the netw or k in any way , including attaching a modem to th e port.
ZyWALL 10 Internet Sec urity G ateway W hat Is a Firewall? 13-1 1 8. Change y our passw ords regularly . Also, use passw ords that are n ot easy to figu re out. The m ost difficult passw ords to crack are those with upper and low er case letters, numbers an d a symbol such as % or #.
.
ZyWALL 10 Internet Sec urity Gate way Introduc ing the Z y W ALL Fire wall 14-1 Chapter 14 Introducing the ZyWALL Firewall This chapt er shows y ou how to get started w ith the Z yWALL Fir ewall. Ple ase see Chap ter 13 for some bac kground i nformatio n on firewa lls.
ZyWALL 10 Internet Sec urity G ateway 14-2 Introduc ing the ZyWALL Firewall Figure 14-3 Menu 21.2 — Firewall Setup Configure the fir ewal l rules u sing the Z yWAL L Web Conf igur ator or CL I comma nds. 14.1.1 View Firewall Log Enter option 3 from menu 21 to view the firewall log.
ZyWALL 10 Internet Sec urity Gate way Introduc ing the Z y W ALL Fire wall 14-3 ICMP Echo A brute-force attack, su ch as a "Smurf" attack, targets a feature in the IP specification known as directed or subn et broadcasting, to quickly fl ood the target network with us eless data.
ZyWALL 10 Internet Sec urity G ateway 14-4 Introduc ing the ZyWALL Firewall T racerou te Traceroute is a utility used to determ ine the path a packet takes between two en dpoints.
ZyWALL 10 Internet Sec urity Gate way Introduc ing the Z y W ALL Fire wall 14-5 Table 14- 4 View Firewall Lo g FIELD DESCRIPTION EXAMPLES # This is the index number of the firewall log. 128 entries are availabl e numbered fr om 0 to 127. Once they are all used, th e log w ill wrap around a nd the old l ogs will be lost.
ZyWALL 10 Internet Sec urity G ateway 14-6 Introduc ing the ZyWALL Firewall Figure 14-5 Big Picture — Filtering, Firewall and N AT 14.3 Packet F iltering Vs Fire w all Below are some comparisons bet ween the ZyWALL’s filtering and fire wall functions.
ZyWALL 10 Internet Sec urity Gate way Introduc ing the Z y W ALL Fire wall 14-7 When T o Use Filtering 1. To block/allow LAN pack ets by their MAC address.
.
ZyWALL 10 Internet Sec urity Gate way Introduc ing the Z y W ALL Web Configura tor 15-1 Chapter 15 Introducing the ZyWALL Web Configurator This chapt er shows y ou how to c onfigure y our fire wall with the W eb C onfigurator . 15.1 Web Configurator Login and Welcome Screens Launch y our web browse r and enter 192.
ZyWALL 10 Internet Sec urity G ateway 15-2 Introduc ing the Z y W ALL Web Configura tor Figure 15-2 ZyWALL We b Configurator Welcome Screen.
ZyWALL 10 Internet Sec urity Gate way Introduc ing the Z y W ALL Web Configura tor 15-3 15.2 Enabling the Firewall Click Firewall , then Configura tion , then the Rule Config tab to enable the firewall as seen in the follo wing screen. Figure 15-3 Enabling the Firewall 15.
ZyWALL 10 Internet Sec urity G ateway 15-4 Introduc ing the Z y W ALL Web Configura tor mail account. Enter the complete e-mail addr ess to which alert messages will b e sent in the E-m ai l Alert s To field and s chedule times for sending alerts in the Alert Timer fie lds in th e E-mail screen (following screen).
ZyWALL 10 Internet Sec urity Gate way Introduc ing the Z y W ALL Web Configura tor 15-5 Table 15- 1 E-mail FIELD DESCRIPTION OPTIONS Address Inform ation Mail Serv er Enter the IP address of y our mail serv er in dotted decimal for mat. Your Intern et Service Provid er (ISP) should be ab le to provi de this info rmation.
ZyWALL 10 Internet Sec urity G ateway 15-6 Introduc ing the Z y W ALL Web Configura tor 15.3.3 SMTP Error Messages If there are diff iculties in sending e-mail the following error messages appear. Please see th e Support Notes on th e included disk f o r information on ot her types of error messag es.
ZyWALL 10 Internet Sec urity Gate way Introduc ing the Z y W ALL Web Configura tor 15-7 Figure 15-5 E-mail Log 15.4 A ttack Alert The first defens e against DOS attacks. In this screen you may choose to generate an alert whenever an attack is detected.
ZyWALL 10 Internet Sec urity G ateway 15-8 Introduc ing the Z y W ALL Web Configura tor 5. Type of traff ic for certain servers . If your network is slower than average for any of these factors (especially if you have servers that are slow or handle many tasks an d are often busy), then th e default values should be reduced.
ZyWALL 10 Internet Sec urity Gate way Introduc ing the Z y W ALL Web Configura tor 15-9 Figure 1 5-6 A ttack A lert The following table describes the fields in this screen.
ZyWALL 10 Internet Sec urity G ateway 15-10 Introduc ing the Z y W ALL Web Configura tor Table 15-3 Attack Alert FIELD DESCRIPTION DEFAULT VALUES Generate alert w hen attack dete cted A detected atta ck automa tically g enerates a log entry. Che ck this box to generate an alert (as w ell as a log) whenever an attack is detected.
ZyWALL 10 Internet Sec urity Gate way Introduc ing the Z y W ALL Web Configura tor 15-1 1 FIELD DESCRIPTION DEFAULT VALUES rises abov e this numb er, the Zy W ALL deletes half-open se ssions as re quired to accommoda te new conne ction reque sts. Do not set Maximum Incomplet e High to lower than t he current Maximu m I ncomplete Low number.
.
ZyWALL 10 Internet Sec urity Gate way Creating C ustom Rules 16-1 Chapter 16 Creating Custom Rules This chapt er cont ains inst ructions for defin ing bot h Local N etwork and I nternet r ules. 16.1 Rules Overvie w Firewall rules are subdiv ided into “Local Network” and “ Internet”.
ZyWALL 10 Internet Sec urity G ateway 16-2 Creating C ustom Rules 5. What computers o n the LAN are to be affected (if any )? 6. What computers on the Internet w ill be affected? The more specific, the better.
ZyWALL 10 Internet Sec urity Gate way Creating C ustom Rules 16-3 16.3 Connection Direction This section talks about con fi gur in g firewall rules for connections going fro m L AN to W AN and WAN to LA N in your fi rewa ll.
ZyWALL 10 Internet Sec urity G ateway 16-4 Creating C ustom Rules Figure 16-2 WAN to LAN Traffic 16.4 Rule Summary The fiel ds in the Rule Su mma ry screens ar e th e same for Loca l Networ k and Int ern et , so the discuss ion below refers to both. Click on Firewall , then Local Ne t work to bring up the followin g scree n.
ZyWALL 10 Internet Sec urity Gate way Creating C ustom Rules 16-5 Figure 16-3 Firewall Rules Summary — First Screen The following table describes the fields in this screen.
ZyWALL 10 Internet Sec urity G ateway 16-6 Creating C ustom Rules Table 16- 1 Firew all Rules Summ ary — Fi rst Screen FIELD DESCRIPTION OPTIONS General Name This is the name of the firewall rule set. Type a name to distinguis h the LAN-to- W AN filt er set from the W AN-to- LAN filter se t.
ZyWALL 10 Internet Sec urity Gate way Creating C ustom Rules 16-7 FIELD DESCRIPTION OPTIONS Click A pply to creat e a new firew all rule. New firewall rul es are added at the end a fter existing firewa ll rules. C lick Edit to edit an ex isting filter rule.
ZyWALL 10 Internet Sec urity G ateway 16-8 Creating C ustom Rules Table 16- 2 Pred efined Serv ices SERVICE DESCRIPTION BGP(TCP:179) Border G ateway Protocol. BOOTP_CLIENT(UDP:68) DHCP Cl i ent. BOOTP_SERVER(UDP:67) DHCP Se rve r. CU-SEEME(TC P/UDP:7648, 24032) A popular vide oconferenc ing soluti on from W hite Pines Softw are.
ZyWALL 10 Internet Sec urity Gate way Creating C ustom Rules 16-9 SERVICE DESCRIPTION SFTP(TCP:115) Simple File Trans fer Protocol. SMT P(TCP:25) Simple M ail Transfer Pr otocol is the messa ge-exchange s tandard for the Inter net. SMTP enables you to mov e messa ges from one e- mail server to another.
ZyWALL 10 Internet Sec urity G ateway 16-10 Creating C ustom Rules 16.5.1 Creating/Editing Firewall Rules To create a new rule, click a n umber ( No. ) then click Edit in the last screen sho wn to display the follo win g screen.
ZyWALL 10 Internet Sec urity Gate way Creating C ustom Rules 16-1 1 Table 16- 3 Creating/ Editing A Firew all Rule FIELD DESCRIPTION OPTIONS Source Address Pr ess SrcA dd to add a new address, SrcEdit to edit an ex isting one or SrcDelete to delete one.
ZyWALL 10 Internet Sec urity G ateway 16-12 Creating C ustom Rules 16.5.2 Source and Destination A ddresses To add a new source or desti nation addres s, click SrcAdd or DestAdd from the screen abov e. To edit an existing source or destin ation address, select it from the box and click SrcEdit or DestEdit from the screen above .
ZyWALL 10 Internet Sec urity Gate way Creating C ustom Rules 16-13 Table 16-4 Adding/Editing Source and Destination Addresses FIELD DESCRIPTION OPTIONS Address Ty pe Do you want your rule to apply to packets w ith a particu lar (single) IP address, a r ange of IP ad dresses (e.
ZyWALL 10 Internet Sec urity G ateway 16-14 Creating C ustom Rules 16.6 T imeout The fiel ds in the Timeout screens are the same for Local and Int ernet netwo rks , so the discussion below refers t o both.
ZyWALL 10 Internet Sec urity Gate way Creating C ustom Rules 16-15 Table 16- 5 Timeout Menu FIELD DESCRIPTION DEFAULT VALUE TCP T imeout Valu es Connectio n Timeout This is the len gth of time t he ZyWALL waits for a TCP session to r each the e stablished st ate before drop ping the sessio n.
.
ZyWALL 10 Internet Sec urity Gate way Custom Ports 17-1 Chapter 17 Custom Ports This chapt er cover s creating , viewing and editi ng custom ports. 17.1 Introducti on Configu re customized ports for services not predefined by the Zy WALL (see Figure 16-4) .
ZyWALL 10 Internet Sec urity G ateway 17-2 Custom Ports Table 17- 1 Custom Ports FIELD DESCRIPTION Customi zed Services No. This is the number of your customiz ed port. Status Indicates whether ports have al ready been co nfigured or are still empty. Name This is the nam e of your c ustomized port.
ZyWALL 10 Internet Sec urity Gate way Custom Ports 17-3 17.2 Creating/Editing A Custom Port Click Edit to create a new custom port or edit an existing on e. This displays the following screen. Figure 17-2 Creating/Editing A Custom Port The next table describes the fields in this screen.
ZyWALL 10 Internet Sec urity G ateway 17-4 Custom Ports Table 17- 2 Creating /Editing A Custo m Port FIELD DESCRIPTION OPTIONS Service Na me Enter a unique nam e for your cu stom port. Service Ty pe Choose the IP port ( TCP , UDP or Bot h ) that defines your customiz ed port from the drop down list box.
ZyWALL 10 Internet Sec urity Gate way Exam ple Firewa ll Rules 18-1 Chapter 18 Logs This chapt er cont ains inf ormatio n about usin g the log s creen to v iew the res ults of th e rules y ou have conf igured.
ZyWALL 10 Internet Sec urity G ateway 18-2 Example F irewall R ules Table 18-1 Log Sc reen FIELD DESCRIPTION EXAMPLES No. This is the index number of the firewall log. 128 entries are av ailable nu mbered from 0 to 127. Once they are all used, th e log w ill wrap arou nd and the old l ogs w ill be lost.
ZyWALL 10 Internet Sec urity Gate way Exam ple Firewa ll Rules 19-1 Chapter 19 Example Firewall Rules This chapt er gives examples f or conf iguring v arious r ules for W AN to LAN and LAN to W AN.
ZyWALL 10 Internet Sec urity G ateway 19-2 Example F irewall R ules Step 1. Activate the firewall. You may activate the firewall through the Zy W ALL Web Configurator as shown ne xt (cli ck Co nfiguration , the Config tab, then ch eck the Firewa ll Ena bled box) or through SMT menu 21.
ZyWALL 10 Internet Sec urity Gate way Exam ple Firewa ll Rules 19-3 Step 2. Co n fi gure yo ur E- mail screen as follo ws. Click the E-mail tab to bring up the next screen. Figure 19-2 Examp l e 1: E-mail Sc re en Enter 10.10 0.1.2, the IP a ddress of the mail server here.
ZyWALL 10 Internet Sec urity G ateway 19-4 Example F irewall R ules Step 3. Co n figure your firewall rule as shown in the following screen. The default firewall blocks all Internet traffic entering our local network, but y ou want to create a hole for web service f rom the Internet.
ZyWALL 10 Internet Sec urity Gate way Exam ple Firewa ll Rules 19-5 Step 4. Clic k DestAdd to configure the destination address as the IP of your s erver on the LAN. Figure 1 9-4 Exampl e 1: Destin ation Address for T raffic Origin ating f rom the Inte rnet 10.
ZyWALL 10 Internet Sec urity G ateway 19-6 Example F irewall R ules Step 5. W hen yo u have finis hed c onfigur in g your r ules, t he Rul e Sum mary sc ree n sho ul d loo k like t hi s. Click Apply i n this screen to save your configuration back to the ZyWALL.
ZyWALL 10 Internet Sec urity Gate way Exam ple Firewa ll Rules 19-7 Step 1. First you want to send alerts when there is an attack. Go to the Attack Alert screen (click Configurat ion , then the Attack Alert tab) shown n ext. Figure 1 9-6 Send Alerts Wh en Atta cked Step 2.
ZyWALL 10 Internet Sec urity G ateway 19-8 Example F irewall R ules Figure 19-7 Configuring A POP Custom Port Step 4. No w, y o u will create rules to block all outgoing traffic (from the local network to the Internet) except for traff ic originating from the HTTP proxy server and our mail serv er.
ZyWALL 10 Internet Sec urity Gate way Exam ple Firewa ll Rules 19-9 Step 5. Clic k SrcAdd under the Source Address box and en ter the IP address of th e mail server (192.168.10. 2) in the sam e fashion as in Figur e 19-4 . Figure 19-8 Example 2: Local Network Rule 1 Configuration Step 6.
ZyWALL 10 Internet Sec urity G ateway 19-10 Exam ple Firewa ll Rules Step 7. The Rule Summary screen sho uld look like Figure 19-9 . Don’ t forget to click Apply wh e n yo u have fi nis he d co n figuri ng yo ur rule ( s) to sa ve your set ting s b ack to the Z yWAL L.
ZyWALL 10 Internet Sec urity Gate way Exam ple Firewa ll Rules 19-1 1 Step 9. On co m pleting the procedure the Rule Summary for this Internet firewall r ules should look like the following screen. Don’t forget to click Apply wh en you ha ve fini shed c o nfi gur in g your rule(s) to save your settings back to the ZyWALL.
ZyWALL 10 Internet Sec urity G ateway 19-12 Exam ple Firewa ll Rules 19.1.3 Exa mple 3: DHCP Negotiation and Syslog Connection from the Internet The following are some Internet firewall rule examples that allow DHCP negotiatio n bet ween the ISP and the ZyWALL 10 and allow a syslog connection from the In ternet.
ZyWALL 10 Internet Sec urity Gate way Exam ple Firewa ll Rules 19-13 Step 2. Fo llo w the procedures outlined in the previous exa mples to co nfigure all your rules. When finished, your rule summary screen should look like the following. Figure 19-12 Syslog Rule Configuration Click Apply whe n fi nish e d.
ZyWALL 10 Internet Sec urity G ateway 19-14 Exam ple Firewa ll Rules Step 3. On co m pleting the procedure the Rule Summary for this I nternet firewall rules should look like the following screen. Don’t forget to click Apply wh en you ha ve fini shed c o nfi gur in g your rule(s) to save your settings back to the ZyWALL.
ZyWALL 10 Internet Sec urity Gate way Content Fi ltering 20-1 Chapter 20 Content Filtering This chapter provides a brief overview of content filtering us ing the Web C onfigurator. For more detailed information , consult the HTML help sectio n of the included disk.
ZyWALL 10 Internet Sec urity G ateway 20-2 Content Fi ltering Figure 20-1 Categor ies Sc reen.
ZyWALL 10 Internet Sec urity Gate way Content Fi ltering 20-3 20.2 Update List Content on the Internet is consta ntly changing, so the content filter list should b e upd a ted o n a weekly basis.
ZyWALL 10 Internet Sec urity G ateway 20-4 Content Fi ltering 20.3 Exempting Computers This screen allows the adm inistrator to include or exclude a rang e of users on the LAN from cont ent filtering.
ZyWALL 10 Internet Sec urity Gate way Content Fi ltering 20-5 20.4 Customizing Customize the content filter list b y adding or removing specific sites fro m the f ilter list .
ZyWALL 10 Internet Sec urity G ateway 20-6 Content Fi ltering 20.5 Ke y w ords The ZyWALL can also be configu red to block certain web sites by using URL keywords .
ZyWALL 10 Internet Sec urity Gate way Content Fi ltering 20-7 20.6 Log Records This screen records the results of your conte nt filter policies. Figure 20-6 Logs Screen.
Troubleshooting, A ppendic es, Glossar y and In dex V Part V: Troubleshooting, Append ices, Glossary and Index Chapter 21 provides inform ation abou t solving c omm on problem s, follo wed by som e Appen dices, a Glossar y of T erms and an Ind ex.
.
ZyWALL 10 Internet Sec urity Gate way Troubleshooting 21-1 Chapter 21 Troubleshooting This chapt er cov ers potent ial prob lems an d possible remedies . After e ach proble m desc ription, some ins tructions are prov ided to he lp you to diagnos e and to s olve the problem.
ZyWALL 10 Internet Sec urity Gate way 21-2 Troubleshootin g 21.2 Problems w ith the LA N Interface Table 21-2 Troubleshooting the LAN Interface Problem Corrective A ction Check the 10M/100M LEDs on the front pa nel. One of these LEDs should be on . If they are both off, ch eck the ca bles betw een your Zy W ALL and hub or the stati on.
ZyWALL 10 Internet Sec urity Gate way Troubleshooting 21-3 21.4 Problems with Internet Access Table 21-4 Troubleshooting Interne t A ccess Problem Corrective A ction Connect your C able/x DSL modem with th e Zy W ALL usi ng appropriat e cable.
.
ZyWALL 10 Internet Sec urity Gate way PPPo E A Appendix A PPPoE PPPoE in Action An AD SL modem bri dges a PPP s ession over Eth ernet (PPP ov er Ethern et, RFC 2516) f rom your PC to an ATM PVC (Permanent Virtual Circuit) which conn ects to a xDSL Access Concentrator where the PPP sess ion term inates (s ee the ne xt figure).
ZyWALL 10 Internet Sec urity Gate way PPPo E B How PPPoE Works The P PPoE dr ive r mak es th e Ethe rnet appear a s a s erial link to the PC and t he PC runs PPP over i t, w hil e the modem bridg es the Ethernet frames to the Access Concentrator (AC ).
ZyWALL 10 Internet Sec urity Gate way PPTP C Appendix B PPTP What is PPT P? PPTP (Poin t-to- Point Tunn eling Prot ocol) is a Micros oft propri etary prot ocol (RFC 2637 f or PPTP i s inf orma tion al only ) to tunn el PPP fra mes .
ZyWALL 10 Internet Sec urity Gate way PPTP D Ac cess C oncentra tor) an d the PPTP us er. Th e PNS i s th e box th at hosts bot h th e PPP and t he PPT P stac ks and forms on e end of the PPTP tunnel. The PAC is the box that dials/answers the phone calls and relays the PPP f ram es to t he PN S.
ZyWALL 10 Internet Sec urity Gate way Hardware Sp ec if ic ati ons E Appendix C Hardware Specifications Power Specifi cation I/P AC 120V / 60Hz ; O/P DC 12V 1200 mA MTBF 100000 hr s Operation T empera.
ZyWALL 10 Internet Sec urity Gate way F Sa fety Ins truc tion s Appendix D Important Safety Instructions The following safety instructions apply to the ZyWALL. 1. Be sure to read and follow all warning notices and instruction s. 2. The maximum recomm ended a mbient temperature for the Zy W ALL is 40º Celsius (104º Fahrenheit).
ZyWALL 10 Internet Sec urity Gate way CLI Comm ands G Appendix E Firewall CLI Commands The follo wing tab le de sc ribe s the s yntax used t o conf igure your fi rewa l l usi ng Co mmand L ine I nterfa c e (CLI) commands. Se lect Men u 24.8 - Command Interpreter Mode from the main menu to go into CLI mode.
ZyWALL 10 Internet Sec urity Gate way H CLI Comm ands Function CLI Syntax Description config edit firewall e-mail email-to <e-mail address> Edits the mail address which you want to send t he alert to.
ZyWALL 10 Internet Sec urity Gate way CLI Comm ands I Function CLI Syntax Description Config edit firewall set <set #> default-permit <forward | block> E di ts whether a packet is dropped or allowed through, when it does not meet a rule within the set.
ZyWALL 10 Internet Sec urity Gate way J CLI Comm ands Function CLI Syntax Description config edit firewall set <set #> rule <rule #> srcaddr-subnet <ip address> <subnet mask> Selects and edits a sourc e address and subnet mask of traffi c which co mply to this ru le.
ZyWALL 10 Internet Sec urity Gate way CLI Comm ands K Function CLI Syntax Description D D e e l l e e t t e e config delete firewall e-mail Rem oves all the settings for e-mai l alert. config delete firewall attack Res ets all the settin gs for attack t o default setting.
ZyWALL 10 Internet Sec urity Gate way L Power Adapt er Specif ic ati ons Appendix F Power Adapter Specifications AC Power Adapter Spec ifications North America AC Power Adapter model M W 48-1201200 Input power: AC120Volts/ 60H z Output pow er: DC12Volts/1.
ZyWALL 10 Internet Sec urity Gate way Power Ad apt er Specif ications M Japan AC Power Adapter model JOD-48-1 124 Input pow er: AC100Volts/ 50/ 60Hz/ 27VA Output pow er: DC12Volts/1.
ZyWALL 10 Internet Sec urity Gate way N Glossa ry of T erms Glossary of T erms 10BaseT The 10-M bps baseband Ethernet specificatio n that uses two pair s of tw isted-pair cabl ing (Category 3 or 5): one pair for transmit ting data an d the other for receiving dat a.
ZyWALL 10 Internet Sec urity Gate way Glossa ry of T erms O Cookie A strin g of charac ters saved by a web brow ser on the us er's hard d isk. Many web pages send cooki es to track specific user infor mation. Cooki es can be used to r etain information a s the user b rowses a web site.
ZyWALL 10 Internet Sec urity Gate way P Glossa ry of T erms Digital Sig nature Digital code that authenticat es whomever signed the document or software. Softw are, messages, E mail, and other electro nic docum ents can b e signed elec tronically so that they cannot be altered by anyone e lse.
ZyWALL 10 Internet Sec urity Gate way Glossa ry of T erms Q Events These are network a ctivities. Som e activities are direct at tacks on your system, while others might be dependi ng on the cir c umstances. T herefore, any a ctivity, regard less of severity i s called an ev ent.
ZyWALL 10 Internet Sec urity Gate way R Glossa ry of T erms Integrity Proof th at the data is th e same as originally in tended. Un authorized softw are or people have not alter ed the original information . internet (Low er case i) Any t ime you conne ct 2 or more networks together, y ou have an i nternet.
ZyWALL 10 Internet Sec urity Gate way Glossa ry of T erms S same as your Eth ernet addr ess.) The M AC layer frame s data for trans mission over t he network, the n passes the fr ame to the physi cal layer interf ace where it is trans mitted as a stream of b its.
ZyWALL 10 Internet Sec urity Gate way T Glossa ry of T erms This cat egory of co mputer crim inal incl udes several d ifferent ty pes of il legal activit ies Making cop ies of softw are for others to use. D istributing pirated softw are over the Internet or a Bul letin Board Sy stem.
ZyWALL 10 Internet Sec urity Gate way Glossa ry of T erms U Proxy Server A server that perfor ms netw ork operations in lieu of other syste ms on the network. Proxy Serv ers are most often u sed as part of a firew all to mask the identity of users inside a cor porate network y et still prov ide acce ss to the Int ernet.
ZyWALL 10 Internet Sec urity Gate way V Glossa ry of T erms security fl aws in th eir netw ork system s. Server A computer , or a softw are package, that prov ides a spe cific kin d of servi ce to client software run ning on other computers .
ZyWALL 10 Internet Sec urity Gate way Glossa ry of T erms W TFTP Trivial File Tr ansfer Proto col is an I nternet file tr ansfer proto col similar to FTP (File Transfer Prot ocol), but it is scaled b ack in fun ctionality so that it requir es few er resource s to run.
.
ZyWALL 10 Internet Sec urity Gate way Index Y Index A Action for M atched Packe ts .......................... 16-11 Activate The F irewall ...................................... 19-3 Alert Schedule ................................................ 15-5 Application-l evel Firewalls .
ZyWALL 10 Internet Sec urity Gate way Z Index E-mail tab ........................................................15-4 Encapsulati on PPP over Ethernet....................................................A Ethernet Encaps ulation3-8, 4-1, 4-5 , 4-6, 4-10, 6- 12, 6-14 Example E-mai l Log .
ZyWALL 10 Internet Sec urity Gate way Index AA Rule Sum mary ................................................... 16-4 log..................................................................... 9-5 Log Facility ...........................................
ZyWALL 10 Internet Sec urity Gate way BB Index Security Ramif ications .....................................16-2 Send Alerts W hen Attacked ............................19-7 Server .................................................................... 3-1, 3-9, 4-2 , 6-3, 6-4, 6-7, 6-9, 6-12, 6-13 , 6- 14, 6-16, 6-17, 11-6, N, U, V Service .
ZyWALL 10 Internet Sec urity Gate way Index CC X xDSL modem ..... 1-3, 1-4, 2-3, 2-4, 4-3, 21-2, 21-3 XMODEM protocol.......................................... 10-2 Z ZyNOS ............. 2-13, 6-4, 6-7, 9- 3, 9-4, 10-1, 10-2 ZyNOS F/ W Version .......
Een belangrijk punt na aankoop van elk apparaat ZyXEL Communications ZYWALL10 (of zelfs voordat je het koopt) is om de handleiding te lezen. Dit moeten wij doen vanwege een paar simpele redenen:
Als u nog geen ZyXEL Communications ZYWALL10 heb gekocht dan nu is een goed moment om kennis te maken met de basisgegevens van het product. Eerst kijk dan naar de eerste pagina\'s van de handleiding, die je hierboven vindt. Je moet daar de belangrijkste technische gegevens ZyXEL Communications ZYWALL10 vinden. Op dit manier kan je controleren of het apparaat aan jouw behoeften voldoet. Op de volgende pagina's van de handleiding ZyXEL Communications ZYWALL10 leer je over alle kenmerken van het product en krijg je informatie over de werking. De informatie die je over ZyXEL Communications ZYWALL10 krijgt, zal je zeker helpen om een besluit over de aankoop te nemen.
In een situatie waarin je al een beziter van ZyXEL Communications ZYWALL10 bent, maar toch heb je de instructies niet gelezen, moet je het doen voor de hierboven beschreven redenen. Je zult dan weten of je goed de alle beschikbare functies heb gebruikt, en of je fouten heb gemaakt die het leven van de ZyXEL Communications ZYWALL10 kunnen verkorten.
Maar de belangrijkste taak van de handleiding is om de gebruiker bij het oplossen van problemen te helpen met ZyXEL Communications ZYWALL10 . Bijna altijd, zal je daar het vinden Troubleshooting met de meest voorkomende storingen en defecten #MANUAl# samen met de instructies over hun opplosinge. Zelfs als je zelf niet kan om het probleem op te lossen, zal de instructie je de weg wijzen naar verdere andere procedure, bijv. door contact met de klantenservice of het dichtstbijzijnde servicecentrum.