Why do I have to block incoming DNS from WAN
I never had to make a rule for incoming DNS request from WAN_to_Zywall, because it is blocked by default. Now I have a Zywall 110 where I did have to make such a rule! If I check the policy Control rules there is nowhere another rule such as WAN_to_Zywall that allows DNS in anyway. The only rule that allows WAN_to_Zywall is my own Fixed IP addresses from office. Are there any hidden rules in Zywall where there still could be an opening?
0
Comments
-
Blocked by default here on my Zywall 110
0 -
Hi @Fender,
By default Zyxel device blocks DNS request that comes from WAN interface for security purposes.
If you want to allow DNS request to Zyxel firewall there are two options we can allow that;
1- Configuration > Security Policy > Policy Control
2- Configuration > Object > Service > Service Group > Default_Allow_WAN_To_ZyWALL
Best regards.0 -
Hi Zyxel_Can, thanks, I willl check it again.0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 148 Nebula Ideas
- 96 Nebula Status and Incidents
- 5.7K Security
- 262 USG FLEX H Series
- 271 Security Ideas
- 1.4K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.4K Consumer Product
- 249 Service & License
- 387 News and Release
- 84 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.5K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 73 Security Highlight