Chapter 25 Firewall
UAG5100 User’s Guide
248
By putting LAN 1 and the alternate gateway (A in the figure) in different subnets, all returning
network traffic must pass through the UAG to the LAN. The following steps and figure describe such
a scenario.
1
A computer on the LAN1 initiates a connection by sending a SYN packet to a receiving server on the
WAN.
2
The UAG reroutes the packet to gateway A, which is in Subnet 2.
3
The reply from the WAN goes to the UAG.
4
The UAG then sends it to the computer on the LAN1 in Subnet 1.
Figure 170
Using Virtual Interfaces to Avoid Asymmetrical Routes
25.2.1 Configuring the Firewall Screen
Click Configuration > Firewall to open the Firewall screen. Use this screen to enable or disable
the firewall and asymmetrical routes, set a maximum number of sessions per host, and display the
configured firewall rules. Specify from which zone packets come and to which zone packets travel to
display only the rules specific to the selected direction. Note the following.
• Besides configuring the firewall, you also need to configure NAT rules to allow computers on the
WAN to access LAN devices. See
for more information.
• The UAG applies NAT (Destination NAT) settings before applying the firewall rules. So for
example, if you configure a NAT entry that sends WAN traffic to a LAN IP address, when you
configure a corresponding firewall rule to allow the traffic, you need to set the LAN IP address as
the destination.
• The ordering of your rules is very important as rules are applied in sequence.