ZyWALL USG-NAT-One-to-One


Setup of NAT-One-to-One

  • Scenario

This guideline describes how to setup 1:1 NAT in ZyWALL USG-series.

ZyWALL USG has some extra IP-addresses available. With 1:1 NAT all requests to e.g. 212.130.62.52 will be directly forwarded to the selected internal client.

ZyWALL USG-series - NAT - One-to-One - 1

  • Start with address objects

To create a NAT One-to-One rule, the simplest way is to start with creating address objects.

In this tutorial we will create two objects, one for the secondary WAN IP-address and one for the server’s internal IP-address.

To create an address object go to the Configurations menu. Select the Object -> Address menu.

Click the Add button.

ZyWALL USG-series - NAT - One-to-One - 2

Give the object a name. Choose Host as Address Type, and insert the secondary WAN IP-address.

ZyWALL USG-series - NAT - One-to-One - 3

Use the same step for the server’s host object.

ZyWALL USG-series - NAT - One-to-One - 4

 

  • Create NAT rule

To create the NAT rule, go to Network -> NAT menu, and click the Add button.

ZyWALL USG-series - NAT - One-to-One - 5

Enable rule. Insert a rule name. Select 1:1 NAT.

Choose the incoming interface (usually WAN1 or ge2).

Select the new Ext_WAN_IP object as Original IP, select Int_SRV_IP as Mapped IP. Set Port Mapping Type as Any.

Click the OK button.

ZyWALL USG-series - NAT - One-to-One - 6

Note: NAT Loopback can be activated, so internal clients can contact server on its public IP-address.

  • Create Firewall rule

As the final step, we need to create a Firewall Rule, to allow traffic pass through to the server.

Go to the Firewall menu, and press the Add button.

ZyWALL USG-series - NAT - One-to-One - 7

Select from WAN to LAN1. Insert your server’s IP-address object as Destination.

Select your preferred Service or Service Group. In this case HTTP is selected.

Set Access as Allow. Enable Log if needed.

Click the OK button.

ZyWALL USG-series - NAT - One-to-One - 8

 

Ricordo che vi e’ un ottimo log che permette di scovare i problemi che possono nascere con la proliferazione delle regole.

Fatto Cio’ riavviate e vedete se tutto funziona correttamente.

Documento Originale


Informazioni / problemi


® Dream Land by Giovanni Bifera


LE INFORMAZIONI CONTENUTE SONO FORNITE SENZA GARANZIA DI ALCUN TIPO, IMPLICITA OD ESPLICITA. L’UTENTE SI ASSUME L’INTERA RESPONSABILITA’ PER L’UTILIZZO DI QUESTE INFORMAZIONI. IN NESSUN CASO SI RENDONO RESPONSABILI PER DANNI DIRETTI, INDIRETTI O ACCIDENTALI CHE POSSANO PROVOCARE PERDITA DI DENARO O DI DATI.


 

 




Numero Di Accessi Alla Pagina: 952

Taggato con: , ,

Lascia un commento

Questo sito usa Akismet per ridurre lo spam. Scopri come i tuoi dati vengono elaborati.