ESR Series Routers Operation Manual
49
For definition of rules for security zones, create 'LAN' address profile that includes addresses which
are allowed to access WAN network and 'WAN' network address profile.
esr(config)#
object-group network WAN
esr(config-object-group-network)#
ip address-range 192.168.23.2
esr(config-object-group-network)#
exit
esr(config)#
object-group network LAN
esr(config-object-group-network)#
ip address-range 192.168.12.2
esr(config-object-group-network)#
exit
esr(config)#
object-group network LAN_GATEWAY
esr(config-object-group-network)#
ip address-range 192.168.12.1
esr(config-object-group-network)#
exit
esr(config)#
object-group network WAN_GATEWAY
esr(config-object-group-network)#
ip address-range 192.168.23.3
esr(config-object-group-network)#
exit
To transfer traffic from 'LAN' zone into 'WAN' zone, create a pair of zones and add a rule allowing
ICMP traffic transfer from PC1 to PC2. Rules are applied with
enable
command:
esr(config)#
security zone-pair LAN WAN
esr(config-zone-pair)#
rule 1
esr(config-zone-rule)#
action permit
esr(config-zone-rule)#
match protocol icmp
esr(config-zone-rule)#
match destination-address WAN
esr(config-zone-rule)#
match source-address LAN
esr(config-zone-rule)#
enable
esr(config-zone-rule)#
exit
esr(config-zone-pair)#
exit
To transfer traffic from 'WAN' zone into 'LAN' zone, create a pair of zones and add a rule allowing
ICMP traffic transfer from PC2 to PC1. Rules are applied with
enable
command:
esr(config)#
security zone-pair WAN LAN
esr(config-zone-pair)#
rule 1
esr(config-zone-rule)#
action permit
esr(config-zone-rule)#
match protocol icmp
esr(config-zone-rule)#
match destination-address LAN
esr(config-zone-rule)#
match source-address WAN
esr(config-zone-rule)#
enable
esr(config-zone-rule)#
exit
esr(config-zone-pair)#
exit
Router always has a security zone named 'self'. When the traffic recipient is the router itself, i.e.
traffic is not transit, pass 'self' zone as a parameter. Create a pair of zones for traffic coming from 'WAN'
zone into 'self' zone. In order the router could response to the ICMP requests from 'WAN' zone, add a rule
allowing ICMP traffic transfer from PC2 to ESR router:
esr(config)#
security zone-pair WAN self
esr(config-zone-pair)#
rule 1
esr(config-zone-rule)#
action permit
esr(config-zone-rule)#
match protocol icmp
esr(config-zone-rule)#
match destination-address WAN
esr(config-zone-rule)#
match source-address WAN_GATEWAY
esr(config-zone-rule)#
enable
esr(config-zone-rule)#
exit
esr(config-zone-pair)#
exit
Create a pair of zones for traffic coming from 'LAN' zone into 'self' zone. In order the router could
response to the ICMP requests from 'LAN' zone, add a rule allowing ICMP traffic transfer from PC1 to ESR:
esr(config)#
security zone-pair LAN self
esr(config-zone-pair)#
rule 1
esr(config-zone-rule)#
action permit
esr(config-zone-rule)#
match protocol icmp