<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Topic &#x27;USG50 Firewall Setting Question&#x27; in forum &#x27;ZyXEL&#x27; - dslreports.com</title>
<link>http://www.dslreports.com/forum/USG50-Firewall-Setting-Question-27974618</link>
<description></description>
<language>en</language>
<pubDate>Sat, 18 May 2013 09:11:04 EDT</pubDate>
<lastBuildDate>Sat, 18 May 2013 09:11:04 EDT</lastBuildDate>

<item>
<title>Re: USG50 Firewall Setting Question</title>
<link>http://www.dslreports.com/forum/Re-USG50-Firewall-Setting-Question-27976222</link>
<description><![CDATA[Brano posted : Yep, I've just tried it myself and the FW rules don't seem to be applied to existing sessions. Only new ones.<br>...I've read through CLI hoping there would be a switch to allow killing all active sessions from / to specified zones but there seems to be none.<br><br>Just realized we've had this discussion already here &raquo;<A HREF="/forum/r27760187-USG100-Weird-and-frightening-firewall-behavior">USG100 - Weird (and frightening) firewall behavior</A><br><br>The problem is non-trivial, the perfect solution would be to have "flush existing session table" command (or similar). ... but I can't find any.<br>Reboot or disabling/enabling the WAN interface seems to be the ugly alternative (the interface disable/enable could be scripted and scheduled (I've not tested this))]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-USG50-Firewall-Setting-Question-27976222</guid>
<pubDate>Sun, 03 Feb 2013 22:01:28 EDT</pubDate>
</item>

<item>
<title>Re: USG50 Firewall Setting Question</title>
<link>http://www.dslreports.com/forum/Re-USG50-Firewall-Setting-Question-27975480</link>
<description><![CDATA[polarisdb posted : <div class="bquote"><said>said by <a href="/profile/649954" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=649954');">Brano</a>:</said><p>The problem is most likely with already established sessions when the rule is activated. This is known issue that some existing sessions don't get killed right away (conclusive testing and proof required).<br> </p></div>I see that with the schedule I have set up to cut off my kids internet access at night.  Existing games, etc. continue to work just fine as long as the connection to the remote server was established before the scheduled firewall rule kicks in.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-USG50-Firewall-Setting-Question-27975480</guid>
<pubDate>Sun, 03 Feb 2013 17:44:50 EDT</pubDate>
</item>

<item>
<title>Re: USG50 Firewall Setting Question</title>
<link>http://www.dslreports.com/forum/Re-USG50-Firewall-Setting-Question-27975294</link>
<description><![CDATA[superataru posted : <div class="bquote"><said>said by <a href="/profile/649954" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=649954');">Brano</a>:</said><p>The problem is most likely with already established sessions when the rule is activated. This is known issue that some existing sessions don't get killed right away (conclusive testing and proof required).<br> </p></div>It should work at the time you apply.<br>Anyway, sometimes it fails ...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-USG50-Firewall-Setting-Question-27975294</guid>
<pubDate>Sun, 03 Feb 2013 16:34:00 EDT</pubDate>
</item>

<item>
<title>Re: USG50 Firewall Setting Question</title>
<link>http://www.dslreports.com/forum/Re-USG50-Firewall-Setting-Question-27975103</link>
<description><![CDATA[Brano posted : The problem is most likely with already established sessions when the rule is activated. This is known issue that some existing sessions don't get killed right away (conclusive testing and proof required).]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-USG50-Firewall-Setting-Question-27975103</guid>
<pubDate>Sun, 03 Feb 2013 15:19:48 EDT</pubDate>
</item>

<item>
<title>Re: USG50 Firewall Setting Question</title>
<link>http://www.dslreports.com/forum/Re-USG50-Firewall-Setting-Question-27975085</link>
<description><![CDATA[tolive posted : Thanks! <br>For this specific rule, is there any difference between Any->WAN and LAN->WAN? My understanding was that the rule should have blocked all internet traffic (unless I have any allow rule set before it).<br><br><div class="bquote"><said>said by <a href="/profile/431519" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=431519');">Anav</a>:</said><p>well I would kinda reverse your rule.<br>I would state it as LAN to WAN block.<br>If there was a particular PC by IP that you wanted to keep access just put an allow rule for that IP before the deny rule.<br><br>I am not sure what happens in the case someone has a session ongoing through the time period however (when it goes from allowed to blocked).<br> </p></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-USG50-Firewall-Setting-Question-27975085</guid>
<pubDate>Sun, 03 Feb 2013 15:11:41 EDT</pubDate>
</item>

<item>
<title>Re: USG50 Firewall Setting Question</title>
<link>http://www.dslreports.com/forum/Re-USG50-Firewall-Setting-Question-27975013</link>
<description><![CDATA[Anav posted : well I would kinda reverse your rule.<br>I would state it as LAN to WAN block.<br>If there was a particular PC by IP that you wanted to keep access just put an allow rule for that IP before the deny rule.<br><br>I am not sure what happens in the case someone has a session ongoing through the time period however (when it goes from allowed to blocked).<br><small>--<br>Ain't nuthin but the blues! "Albert Collins". <br>Leave your troubles at the door! "Pepe Peregil" De Sevilla.  Just Don't Wifi without WPA, "Yul Brenner"<br><br><A HREF="http://www.llamaworks.ca">LlamaWorks Equipment</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-USG50-Firewall-Setting-Question-27975013</guid>
<pubDate>Sun, 03 Feb 2013 14:40:16 EDT</pubDate>
</item>

<item>
<title>USG50 Firewall Setting Question</title>
<link>http://www.dslreports.com/forum/USG50-Firewall-Setting-Question-27974618</link>
<description><![CDATA[tolive posted : I set up the above firewall rule trying to block internet access from all my home PCs during a defined schedule, while it does block most internet access, I found that the firewall rule doesn't block certain type of instant messenger (specifically, the "QQ" which is the most popular instant messenger in China), what's wrong with my rule settings? <div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/27974618?c=2071706&ret=L2ZvcnVtL3IyNzk3NDYxOC54bWw%3D"><IMG TITLE="37946 bytes" BORDER=0 WIDTH=477 HEIGHT=429 SRC="/r0/download/2071706~616be4471e139e661592b5975f185ef1/firewall.png"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/USG50-Firewall-Setting-Question-27974618</guid>
<pubDate>Sun, 03 Feb 2013 12:27:48 EDT</pubDate>
</item>

</channel>
</rss>
