beautypg.com

2 configuring a tcp/ip filter rule, Figure 351 menu 21.1.1.1: tcp/ip filter rule, Table 225 menu 21.1.1.1: tcp/ip filter rule – ZyXEL Communications ZyXEL ZyWALL 2WG User Manual

Page 560

background image

Chapter 39 Filter Configuration

ZyWALL 2WG User’s Guide

560

39.2.2 Configuring a TCP/IP Filter Rule

This section shows you how to configure a TCP/IP filter rule. TCP/IP rules allow you to base
the rule on the fields in the IP and the upper layer protocol, for example, UDP and TCP
headers.
To configure TCP/IP rules, select TCP/IP Filter Rule from the Filter Type field and press
[ENTER] to open Menu 21.1.x.x - TCP/IP Filter Rule, as shown next.

Figure 351 Menu 21.1.1.1: TCP/IP Filter Rule

The following table describes how to configure your TCP/IP filter rule.

Menu 21.1.1.1 - TCP/IP Filter Rule

Filter #: 1,1
Filter Type= TCP/IP Filter Rule
Active= Yes
IP Protocol= 0 IP Source Route= No
Destination: IP Addr=
IP Mask=
Port #=
Port # Comp= None
Source: IP Addr=
IP Mask=
Port #=
Port # Comp= None
TCP Estab= N/A
More= No Log= None
Action Matched= Check Next Rule
Action Not Matched= Check Next Rule

Press ENTER to Confirm or ESC to Cancel:

Table 225 Menu 21.1.1.1: TCP/IP Filter Rule

FIELD

DESCRIPTION

Active

Press [SPACE BAR] and then [ENTER] to select Yes to activate the filter rule or No

to deactivate it.

IP Protocol

Protocol refers to the upper layer protocol, e.g., TCP is 6, UDP is 17 and ICMP is 1.

Type a value between 0 and 255. A value of 0 matches ANY protocol.

IP Source Route Press [SPACE BAR] and then [ENTER] to select Yes to apply the rule to packets

with an IP source route option. Otherwise the packets must not have a source route

option. The majority of IP packets do not have source route.

Destination

IP Addr

Enter the destination IP Address of the packet you wish to filter. This field is ignored

if it is 0.0.0.0.

IP Mask

Enter the IP mask to apply to the Destination: IP Addr.

Port #

Enter the destination port of the packets that you wish to filter. The range of this field

is 0 to 65535. This field is ignored if it is 0.