-
What is the difference between Virtual Server and 1:1 NAT?
Question I would like to use NAT feature to publish an internal server for external users. On the NAT Add/Edit page, there are Virtual Server and 1:1 NAT. Which one should I choose? What is the difference between Virtual Server and 1:1 NAT? Answer Both Virtual Server and 1:1 NAT are able to publish internal servers to…
-
Implement Inbound Server Load Balance
Inbound Server Load
Balance For load Balance or redundant purpose, some enterprises might have more than one ISP or Web Server to handle
incoming service requests. This article will explain how to achieve the goal on
Zyxel Firewall. Before Begin Firewall uses Algorithm to respond to a DNS query with the IP address…
-
How to set a range of IP addresses on USG interface?
Scenario: My ISP provided me a range of public IP addresses. (10 public IP addresses)I would like to set these IP addresses on USG, but USG only supports up to 4 virtual interfaces. How can I set that on USG? I would like to publish 10 servers to the Internet. Configuration: If ISP provided a range of IP addresses, you can…
-
What is the procedure to configure SBG3300 for WOL (Wake on LAN)?
Scenario: The User A wants
to use WOL (Wake on LAN)
feature to awake the Target
PC from Port:
8080 at SBG3300 WAN side. To meet this requirement, SBG3300 should add NAT rule &
Static ARP for the target
PC. What is the procedure to configure SBG3300
for this purpose? Step-by-Step: Step 1: Go
to Network Setting > NAT > Port…
-
How to setup port forwarding to my internal RDP PC?
You can add the virtual server rule for your requirement: (1) Original IP: The IP address your ISP provided. (2) Mapped IP: The IP address your Server IP. (3)Original port: The port number which you would like to connected from outside. (4)Mapped port: The port number which your server is servicing. And make sure your…
-
How to Allow Public Access to a Server Behind ZyWALL/USG?
SCENARIO DESCRIPTION: This is an example of using ZyWALL/USG to configure a securely access to internal server behind ZyWALL/USG with network address translation (NAT). The Internet users can reach this server directly by its public IP address and a NAT mapping rule will forward the traffic from the Internet to the…
-
Why the USG trunk profile cannot work as expect, the traffic always went to wrong interface?
Please check policy route rule trunk profile status, dead or alive. The status depends on Interface “Connectivity Check”, what if you set up an improper host to perform connectivity Check, it always in dead status, that why the traffic always go to wan 2. Try to adjust a suitable one as “connectivity check” host and try it…
-
Why is it that the SIP voice does not pass through the SIP server?
Question I have a SIP server at the LAN site with three SIP phones, Phone#A and Phone#B in the LAN site, and Phone#C at the external site. The connection between Phone#A and Phone#B works fine. The connection between the internal Phone and Phone#C fails. What is the cuase of this problem? Answer This is because; currently,…
-
How can the inbound destination NAT be used to hide the server’s real IP via a VPN tunnel?
A customer requires that the server’s real IP is hidden when using site-to-site VPN. This can be done by using an inbound destination NAT to hide the server’s real IP when VPN is established. The inbound DNAT works as a virtual server. It can redirect the VPN traffic to the internal server. Steps: VPN connections: Policy…
-
When creating 1:1 NAT rules for local hosts, these local hosts become unreachable through VPN IPSec.
The virtual server function is a "port forwarding" function. The 1:1 NAT function is "forwarding all traffic" to the local server. When using "1:1NAT", the traffic can't pass through to the tunnel because all traffic passes through the WAN interface.In "packet flow explore", the priority of 1-1 SNAT is higher than site to…
-
WRR mechanism
WRR uses "session" for weighting, not traffic loading. If WRR is configured with WAN 1 weight 3 and WAN 2 weight 1, it doesn't mean that there should be 3 times of traffic loading coming in from WAN 1 compared to WAN 2.The value of session weight may not be equal to that of the traffic load. One session may consume more…
-
The procedure to indicate specific traffic go through specific wan interface
SCENARIO DESCRIPTION:On the USG, what is the procedure to configure WAN 1 for all traffic except VPN traffic, and WAN 2 for VPN traffic without failover? SETUP/STEP BY STEP PROCEDURE:1. Create a VPN gateway and VPN connection based on WAN 2. 2. Ensure that both WAN 1 and WAN 2 are in the WAN trunk. 3. Add rule 1 and rule 2…
-
How to Configure Bandwidth Management for FTP and HTTP Traffic?
SCENARIO DESCRIPTION:This is an example of using ZyWALL/USG Bandwidth Management (BWM) to control the bandwidth allocation for FTP and HTTP traffic. You can use source interface, destination interface, destination port, schedule, user, source, destination information, DSCP code and service type as criteria to create a…