Facts: ZyWALL can not decrypt HTTPS, DoH, DoT, etc.
then: can not protect from new malware
Facts: ZyWALL can have some bad DNS list
then: ZyWALL can not see inside DoH, DoT, etc.
then: can not protect from visiting unwanted or risky sites
Facts: ZyWALL can not decrypt email sended or received by "STARTTLS" or other SSL/TLS transmission/reception methods.
then: ZyWALL can not see inside email
then: can not protect from old or new malware
Facts: ZyWALL can not decrypt social traffic (for ex. whatsapp)
then: ZyWALL can not see inside social traffic (for ex. whatsapp)
then: can not protect from idiot user
Facts:
Neither MikroTik can do that
then: The only thing can both do, and with success, is blocking IP from blacklists.
if it was my network, what would i do until the subscription expires:
Remove ZyWALL from the balls.
But if I see someone ask to leave it on play forcefully:
ISP "modem" -> ZyWALL "Hoax" -> RB1100Dx4 -> CRS326-24G-2S+ -> LAN
ISP "modem" give the Public IP directly to RB1100Dx4,
ZyWALL "Hoax" check the connection between RB1100Dx4 and the ISP "modem"
RB1100Dx4 act already as firewall with default rules and make the routing and NAT for the LAN
Internal LAN are connected at wire speed
ISP "modem" ether -> etherin ZyWALL "Hoax" etherout -> ether1 RB1100Dx4 ether2 -> ether1 CRS326-24G-2S+ (all remaining ether2..ether24) -> LAN
On future, when ZyWALL "Hoax" go out of the balls:
sfp1+
fiber cable ───────────────┐
CRS326-24G-2S+ RB1100Dx4
sfp2+ unused ││└─────────────────┘││ ether11 and ether12 unused
││ ether24-ether13 ││
││ ││
│└───────────────────┘│
│ ether1-ether1 │
│ │
LAN (ether1..23) LAN (ether1..5) + limited speed (by CPU) LAN (ether6..10)
ISP "modem" function as media converter moved to SFP+ on CRS326-24G-2S+
RB1100Dx4 act as "modem" and firewall with default rules and make the routing and NAT for the LAN
Internal LAN are connected at wire speed
fiber cable -> sfp1 CRS326-24G-2S+ ether24 -> ether13 RB1100Dx4 ether1 -> ether1 CRS326-24G-2S+ (all remaining ether2..ether23) -> LAN
or better if have also S-RJ01:
sfp1+
fiber cable ───────────────┐
CRS326-24G-2S+ RB1100Dx4
││ └──────────────┘││ ether11 and ether12 unused
││ sfp2+ -ether13 ││
││ ││
│└───────────────────┘│
│ ether1-ether1 │
│ │
LAN (ether1..24) LAN (ether1..5) + limited speed (by CPU) LAN (ether6..10)
but if ISP "modem" must remain, link to RB1100Dx4 directly on ether13
ether13
fiber cable ──────────────────────────┐
│
CRS326-24G-2S+ RB1100Dx4
sfp1+ & sfp2+ unused │└───────────────┘│ ether11 and ether12 unused
│ ether1-ether1 │
│ │
LAN (ether1..24) LAN (ether1..5) + limited speed (by CPU) LAN (ether6..10)
but if ISP "modem" must remain, and you have S-RJ01 to use, the best is
ether13
fiber cable ──────────────────────────┐
│
CRS326-24G-2S+ RB1100Dx4
sfp2+ unused │ └───────────┘│ ether11 and ether12 unused
│ sfp1+ -ether1 │
│ │
LAN (ether1..24) LAN (ether1..5) + limited speed (by CPU) LAN (ether6..10)
all considerations are based on block diagram of both devices:
https://i.mt.lv/cdn/product_files/RB110 ... 170842.png
https://i.mt.lv/cdn/product_files/CRS326_180248.png