FLEX500: Match default rule DNAT Packet, DROP

Hello,

Can anybody explain that type of log like below:?

Match default rule DNAT Packet, DROP  source: 192.168.100.12 --- dest.: 192.168.100.1

I haven't any NAT service to that subnet configured.
I have one NAT rule but destination address is in different subnet (different vlan)

All Replies

  • smb_corp_user
    smb_corp_user Posts: 36
    First Comment First Answer Friend Collector
     Freshman Member
    https://community.zyxel.com/en/discussion/3993/match-default-rule-dnat-packet-drop

    Not sure how much it helps, but at least it can give you a little bit of insight to what the parts can be. You may also want to review the list of rules to see if any of them affect the NAT behaviour.
  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,100
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 50 Answers 1000 Comments
     Guru Member
    Hi @tomeC,

    Does your firewall have any interface binding subnet 192.168.100.X/24?
    Moreover, please help to check if there are any physical cable attached between lan and wan switch.
  • tomeC
    tomeC Posts: 4
    First Comment First Anniversary
    edited December 2022
    1. Yes, interface is in DMZ zone (base port also dmz)
    2. No, there is no physical cable between LAN and WAN

  • tomeC
    tomeC Posts: 4
    First Comment First Anniversary
    I found that CDR security service is a cause of it. After disabling there is no more problems. Actually that scope (192.168.100.X/24) belongs to vlan which is in Qarantine VLAN ID in CDR settings, but I cant remove it - can't set it to "none"?

    Can anybody explain this behaviour?

  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,100
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 50 Answers 1000 Comments
     Guru Member
    Hi @tomeC,

    Can you send me startup configuration in pm for further checking. 
    Thanks.

Security Highlight