Help

Associating "Host" Zones to Interfaces

If you have assigned the special zone "-" to an interface, you need now to define the "host" zones for that interface. A "host" zone is merely a group of machines identified by their common subnet. It can be reduced to a single machine.

Host ID: This ID number will be used everywhere needed to uniquely identify the host zone.
Zone: Choose the zone name to use for this host zone in the pull-down list.
Interface: Choose the interface associated to this host zone in the pull-down list. Choose "+" if you don't want to associate a particular interface to the zone address or subnet. Note: Use of "+" weakens the firewall slightly and increases packet latency slightly.
IP Address: The host or subnet address for the machines associated to this host zone. Example: "192.168.2.0/2".
options: The "routestopped" option, if checked, has the following effect: When the firewall is stopped, traffic to and from this host (these hosts) will be accepted and routing will occur between this host and other routestopped interfaces and hosts.

Example: you wish to have some precise machines of the local network to be able to administer the firewall, even if the firewall is stopped. After having configured the local "eth2" interface as being assigned the special zone "-" with option "multi", you now need to configure the special host zone "adm" corresponding to only some machines of the local subnetwork.

Zone: adm
Interface: eth2
IP Address: 192.168.1.0/25
options: routestopped