(1) Type CI “ip icmp death 1000” or “ip icmp death 1500”.
(2) PC1 ping PC2 with DOS command “ping 172.25.21.254 –l 1600”, the
log is shown as: “ping of death. ICMP(Echo)”.
(3) Type CI “ip icmp death 1501” or other number bigger than 1500.
(4) PC1 ping PC2 with DOS command “ping 172.25.21.254 –l 2000”, the
log is shown as: “
ping of death. ICMP(Echo Reply)”. That is to say
when argument in CI “ip icmp death” is bigger than 1500, the log is
different. And sometimes the log shown as “
ping of death. ICMP(W to L,
Echo Reply)
”.
3. For traffics which ports are dynamic negotiated, we can only block them from WAN
to LAN/DMZ/WLAN if LAN/DMZ/WLAN to WAN default action of Firewall is
Permit. The reason is that those traffics from LAN/DMZ/WLAN to WAN will match
the default action. But most of software will disconnect the session since they found
something wrong, which caused by we blocked traffics from WAN.
[UPnP]
1. Sometimes on screen the “Local Area Connection” icon for UPnP disappears. The
icon shows again when restarting PC.
2. When you use MSN messenger, sometimes you fail to open special applications, such
as whiteboard, file transfer and video etc. You have to wait more than 3 minutes and
retry these applications.
[VPN]
1. SNMP tools get ZYWALL VPN MIB data, the index of received data are wrong if
rules are larger than 1.
2. VPN rule swap does not support NAT Traversal.
[MISC]
1. The DMZ TxPkts counter increment at about 1 pkt/min even without any Ethernet
cables ever connected.
2. In eWC->Statistics, Tx data for Dial Backup is not correct.
3. ZyWALL does not support WAN 1/WAN 2 on the same sub-net. (For Multiple WAN
products)
[LOGS]
Symptom: When fail to connect SMTP server some times, then ZyWALL couldn’t send
Log successful anymore although you configurations are correct.
Condition:
(1) sys log load
(2) sys log mail port 1000
(3) sys log save
(4) In eWC>>LOGS>>Log Setting, set:
a) Mail Server = ms01.zyxel.cn
Comentarios a estos manuales