TMS zl Module Installation and Getting Started Guide 2010-03
2-2
Getting Started
• Application-Level Gateway (ALG)
• Network Address Translation (NAT)
■ Intrusion Prevention (IPS)
■ Virtual Private Network (VPN)
■ High Availability (HA)
■ Network authentication
The monitoring mode provides the following features:
■ Intrusion Detection (IDS)
■ High Availability (HA)
Note A TMS zl module operates in only one mode. If the operating mode is switched
from one mode to the other, the module reverts to the factory defaults for the
new mode, or to any settings previously configured for that mode.
Traffic Management
The TMS zl module uses zones and Virtual LANs (VLANs) to control traffic.
Zones are logical groupings of VLANs or interfaces. Zones enable you to create
common firewall, VPN, or NAT policies that apply to all VLANs that are
members of the zone.
A TMS VLAN is a VLAN assigned to a zone. TMS VLANs can be associated with
only one zone at a time. To associate a VLAN with a zone, that VLAN must
exist on the module’s host switch.
Zones
The TMS zl module supports two types of zones:
■ Self zone
Traffic that is destined to any IP address that is configured on the TMS zl
module itself. It includes:
• Management traffic
• Internet Key Exchange (IKE) traffic for establishing VPNs for which
the TMS zl module is the gateway
• Routing updates
• Traffic that is destined to an IP address on the module and to which
destination NAT is applied
zlSM.book Page 2 Monday, March 1, 2010 11:42 PM