Skip to main content

Firewall configuration options

This page describes the settings available on each configuration page for a NetFoundry zLAN firewall.

Details page

The Details page shows a read-only summary of the firewall instance.

FieldDescription
NameThe display name of the firewall.
DescriptionAn optional description.
StatusCurrent operational state: Online, Offline, or Not configured.
InterfacesNetwork interfaces available for configuration.

Configuration page

The Configuration page controls global and per-interface settings.

General settings

SettingDescription
Discovery modeEnable or disable network discovery on an interface.
Allow ICMPPermit inbound and outbound ping (ICMP echo) traffic.
Allow SSHPermit inbound SSH connections to the firewall.
Masquerade (NAT)Enable source NAT so that traffic leaving the firewall uses the interface IP.
VRRPEnable VRRP for high-availability failover.
OSPFEnable the Open Shortest Path First dynamic routing protocol.
EIGRPEnable the Enhanced Interior Gateway Routing Protocol.

DHCP server settings

These settings apply per interface. The gateway defaults to the interface IP address.

SettingDescription
Default lease timeDefault duration (in seconds) for DHCP address leases.
Maximum lease timeMaximum duration (in seconds) a client may request for a lease.
DNS server 1Primary DNS server address assigned to DHCP clients.
DNS server 2Secondary DNS server address assigned to DHCP clients.
Range startFirst IP address in the DHCP pool.
Range endLast IP address in the DHCP pool.
Subnet maskSubnet mask assigned to DHCP clients.

Rules page

The Rules page lists all active firewall rules. Each rule can be configured with the following fields.

FieldDescription
ProtocolThe network protocol the rule applies to (TCP, UDP, ICMP, or any).
SourceSource IP address or CIDR range.
DestinationDestination IP address or CIDR range.
PortDestination port or port range.
ActionAllow or Deny.
PriorityEvaluation order — lower numbers are evaluated first.

To manage rules, see Manage firewall rules.

Visualize page

The Visualize page provides a graphical view of the firewall's configuration and active traffic flows, including which interfaces and rules are in use.