Easier way to configure security policies for Zoom?

rookierunner
Posts: 23
Freshman Member




in Security
I am looking to add the appropriate security policies, etc. to configure my Zywall 110 based on the the network firewall guidance that Zoom provides (https://support.zoom.us/hc/en-us/articles/201362683-Network-firewall-or-proxy-server-settings-for-Zoom). They list a ton of IP addresses for various ports/services. It would be vary tedious to manually enter all of this information to configure the firewall appropriately. Looking for if there is an easier way? (Note: I have all outbound traffic blocked, except for ports/services that I explicitly open up. Maybe that's overkill but I view it as cautious.)
0
All Replies
-
Hi @rookierunner,Here is the specification of ZyWALL 110 for your reference.Address Object: 300Address Group: 50Max. Address Object In One Group: 128The maximum number of address object can be created on ZyWALL 110 is 300.However, there are more than 1000 IP addresses in the firewall guidance that Zoom provides.You need to use Class B to combine several address into subnet.For example:Create address object 13.32.0.0/16 for the following addresses.13.32.10.24313.32.101.25313.32.105.249......13.32.224.24913.32.229.24113.32.24.249Open console or SSH.Router> configure terminalThen copy the following commands and paste them via console/SSHaddress-object addr1 13.32.0.0 255.255.0.0address-object addr2 13.33.0.0 255.255.0.0....write1
-
Thanks, Emily. It is still a lot of manual configuration so I will have to decide how much effort I will put into managing the ports to IP addresses. It would be great if Zyxel would give their firewalls the ability to load preconfigured rule sets and also provide these preconfigured rule sets for major services like Zoom, Apple services (FaceTime, etc.), Google Voice, etc. I know probably not going to make the product roadmap but I can hope.0
-
Hi @rookierunner,Thank you very much for your suggestion. We will evaluate it in the future.0
-
Hi rookieruner,if I understand correctly, you have problem with the connection and Zoom ("Network error, please try again") ? We use Zoom on USG 110 on our network without these settings ...
0 -
@kyssling - the issue is that I lock down the outbound ports, not just the inbound ports. I am guessing that you allow all traffic outbound so that makes sense that you don’t have the issue. I allow only certain outbound traffic to limit potential data leak, unwanted tracking, etc.0
-
I do the same for one of my USG I have not fully tested this but if you do a Address WILDCARD FQDN with *zoom.us destination firewall that might allow all the addresses needed for zoom.0
Categories
- All Categories
- 415 Beta Program
- 2.5K Nebula
- 152 Nebula Ideas
- 103 Nebula Status and Incidents
- 5.8K Security
- 297 USG FLEX H Series
- 282 Security Ideas
- 1.5K Switch
- 77 Switch Ideas
- 1.1K Wireless
- 42 Wireless Ideas
- 6.5K Consumer Product
- 254 Service & License
- 396 News and Release
- 85 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 87 About Community
- 76 Security Highlight