USG110 - Lack of understanding "ANY to WAN" vs. "ANY to ZyWall"
All Replies
-
Hi @USG_User
The “any” is meaning all of the zones except “ZyWALL” zone.
It will include: all of intra zones and WAN zone.
The ZyWALL zone is means firewall itself.
There are many build-in service: SSH/TELNET/FTP/HTTP/HTTPS/DNS…..etc.
You can allow or deny traffic those come from “Any” zone to access build-in service.
In your case, if you would like to deny DNS query from WAN side.
You can create this rule to block DNS query:
From: WAN. To: ZyWALL, Service: DNS, Action: Deny.
0 -
Hi Stan,Thanks for your reply. The obove mentioned rule is clear so far, but doesn't explain what I'm interested in. Further we don't maintain a "Deny strategy" where all is allowed until we define a Deny rule. With us, all is denied by a default rule until we allow traffic by a separate rule.When creating a rule "Any to WAN", does it includes "WAN to WAN", too? In our DNS example, does it mean that external DNS queries from Internet to our public IP will be redirected by USG back to the internet again? This would be the thinking, if you say "ANY" contains always also the WAN zone.When allowing DNS queries from all internal zones to the internet, I would like to use "Any to WAN" to save different single rules for all internal zones to WAN. But in that case "Any to WAN" should exclude "WAN to WAN" since "WAN" is already set as destination in "ANY to WAN", isn't it?0
-
Hi @USG_User
As your question: does it mean that external DNS queries from Internet to our public IP will be redirected by USG back to the internet again?
The answer is not. Because the public IP address of USG is belonging to USG itself.
So it is “ZyWALL” zone but not WAN zone.
0
Categories
- All Categories
- 347 Beta Program
- 2.1K Nebula
- 114 Nebula Ideas
- 77 Nebula Status and Incidents
- 5K Security
- 44 USG FLEX H Series
- 246 Security Ideas
- 1.2K Switch
- 64 Switch Ideas
- 901 WirelessLAN
- 33 WLAN Ideas
- 5.8K Consumer Product
- 204 Service & License
- 326 News and Release
- 71 Security Advisories
- 21 Education Center
- 5 [Campaign] Zyxel Network Detective
- 1.8K FAQ
- 831 Nebula FAQ
- 401 Security FAQ
- 219 Switch FAQ
- 190 WirelessLAN FAQ
- 45 Consumer Product FAQ
- 136 Service & License FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 71 About Community
- 61 Security Highlight