How to reach an external server on a USG1100 firewall

Matt10669 Posts: 20  Freshman Member
Second Anniversary Zyxel Certified Network Administrator - Security 10 Comments
Hi, I need to reach an external server (IP through the ports 80 and 443 of a USG1100 firewall from the clients of my LAN. At the moment the firewall blocks the outgoing flow. I found lot of guides about NAT service for incoming packets to an internal server but nothing about the opposite. I have to go out from LAN to WAN. Any explanations or helps will be very appreciated.

All Replies

  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,511  Zyxel Employee
    100 Answers Sixth Anniversary 1000 Comments Zyxel Certified Sales Associate
    edited October 2022
    Hi @Matt10669,

    Can you see any blocked log at MONITOR > Log > View Log when filtering keyword ""?

    Don't miss this great chance to upgrade your Nebula org. for free!

  • PeterUK
    PeterUK Posts: 3,152  Guru Member
    Community MVP 2500 Comments Sixth Anniversary 100 Answers
    edited October 2022

    By default LAN to WAN is all allow out by policy control, do any clients of your LAN have internet access?

  • Matt10669
    Matt10669 Posts: 20  Freshman Member
    Second Anniversary Zyxel Certified Network Administrator - Security 10 Comments
    All my clients have internet access. I forgot to mention that in my LAN we have configured 2 VLAN's. I dont know if this can be important
  • Hi @Matt10669,

    Can you see any blocked log at MONITOR > Log > View Log when filtering keyword ""?

    Thanks for Sharing Really Appreciated..... 
  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,511  Zyxel Employee
    100 Answers Sixth Anniversary 1000 Comments Zyxel Certified Sales Associate
    Hi @Matt10669,
    Please help to test access again and capture packets on USG1100 wan interface. 
    We would like to check why it is fail to access.

    MAINTENANCE > Diagnostics > Packet Capture.
    Interface = External wan interface
    Host IP =
    Download packets in "Files" tab and send me in PM for further analzying.

    Don't miss this great chance to upgrade your Nebula org. for free!

  • Matt10669
    Matt10669 Posts: 20  Freshman Member
    Second Anniversary Zyxel Certified Network Administrator - Security 10 Comments
    I checked and I don't have any block in the log monitor. But the service doesn't work. If I connect my lan directly into the router bypassing the firewall the service works. Very strange
  • Matt10669
    Matt10669 Posts: 20  Freshman Member
    Second Anniversary Zyxel Certified Network Administrator - Security 10 Comments
    Cooldia I've sent you what you asked. Thank you so much

Security Highlight