How to configure Virtual server (NAT) with security policy?
Zyxel_Chris
Posts: 705 Zyxel Employee
In most cases, you don't need to configure the firewall rule if there is no virtual server (NAT) rule. NSG has the default rule (running in background) to block the traffic from WAN to LAN.
If there is a NAT rule, you can put trust IP in the "Allowed Remote IP" which is equal to a whitelist.
In Configure > Security gateway > Firewall > NAT > Virtual server, it can fill in a "," syntax for adding multiple IP addresses.
You can still use security policy to block unfriendly traffic If the client IP is not static or in your permit rules.
For instance, the source IP from 10.214.30.13 tries to access this virtual server which is not allowed.
VS_0 means the first entry of the virtual server rule.
Configure the security policy to block an IP address.
Source IP "10.214.30.13" destination IP is "192.168.40.35, Policy action select as "Deny".
Go to the event log and filter the firewall category, and you will see a log that contains "Priority: 1 from any to any" where the priority is the security policy entry. Check the source and destination IP is the same as what we have configured in above steps.
This access action has been denied by NSG firewall rule.
Configure the security policy to block an IP address.
Source IP "10.214.30.13" destination IP is "192.168.40.35, Policy action select as "Deny".
Go to the event log and filter the firewall category, and you will see a log that contains "Priority: 1 from any to any" where the priority is the security policy entry. Check the source and destination IP is the same as what we have configured in above steps.
This access action has been denied by NSG firewall rule.
Tagged:
0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 144 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.6K Security
- 237 USG FLEX H Series
- 267 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.3K Consumer Product
- 246 Service & License
- 383 News and Release
- 83 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.2K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight