181
4.7.2.4 Set Up a DMZ to LAN Firewall Rule for SIP
The firewall blocks traffic from the DMZ zone to the LAN1 zone by default so you need to create a
firewall rule to allow the IPPBX to send SIP traffic to the SIP clients on the LAN.
1 Click Configuration > Firewall > Add. Set the From field as DMZ and the To field as LAN1. Set the
Destination to the IPPBX’s DMZ IP address object (DMZ_SIP). Set the Source to IPPBX_DMZ.
Leave the Access field to allow and click OK.
4.7.3 What Can Go Wrong
• The USG checks the firewall rules in order and applies the first firewall rule the traffic matches. If
traffic matches a rule that comes earlier in the list, it may be unexpectedly blocked.
• The USG does not apply the firewall rule. The USG only apply’s a zone’s rules to the interfaces
that belong to the zone. Make sure the WAN interface is assigned to WAN zone.
4.8 How to Limit Web Surfing and MSN to Specific People
The following is an example of using application patrol (AppPatrol) to enforce web surfing and MSN