6. How do I set up ZoneAlarm Pro to work on an ICS system?
On the ICS gateway machine, ZoneAlarm Pro needs two specific settings to ensure the ICS clients will have access. Otherwise, ZoneAlarm Pro on the gateway will block client access.
In ZoneAlarm Pro, on the ICS gateway machine:
- Step 1. Go to the Security panel.
- Step 2. Select "Advanced."
- Step 3. Go to the "General" tab.
- Step 4. Click "This computer is an ICS gateway". The local gateway address 192.168.0.1 should appear in the Local Address combo box. The internet IP address will also appear in the list, but 192.168.0.1 is what should be selected.
- Step 5. Go to the "Local zone Contents" tab.
- Step 6. In the "Adapter Subnets" list, check the checkbox for the network card that the local network is connected to (the one with the 192.168.0.1 address). Do not check the adapter that connects the gateway to your modem.
- Step 7. Click "Apply" or "OK" for these two settings. That is the minimum that is required for ZoneAlarm Pro installed on the ICS gateway machine.
On the ICS server, be sure that the checkboxes to allow outgoing DNS and outgoing DHCP are checked. You can find these in the Security panel. Click Advanced, then "Internet Zone Custom Settings" tab.
ZoneAlarm Pro does not have to be installed on the ICS clients. But if the clients would like to see ZoneAlarm Pro alerts, have the client machine(s) protected by ZoneAlarm Pro, control outbound connections from client applications, or perhaps have more stringent security than the gateway's ZoneAlarm Pro settings, then install ZoneAlarm Pro on the client machine(s) and:
- Step 1. Go to the Security panel.
- Step 2. Click "Advanced."
- Step 3. Go to the "General" tab.
- Step 4. Click "This computer is a client of an ICS gateway running ZoneAlarm Pro." The gateway address 192.168.0.1 should appear in the Gateway Address combo box.
- Step 5. Check "Forward alerts from gateway to this computer" if you would like to see the alerts on the client machine.
- Step 6. Go to the "Local Zone Contents" tab.
- Step 7. In the "Adapter Subnets" list, check the checkbox for the network card that connects the client to the gateway.