ZyWALL 110: Why are pfw's for WAN1 active on WAN2 as well? (2 different IP's, same ISP)
Best Answers
-
Hi @jwladd
In your NAT rule, you did not setup correct IP address in external IP so traffic will forward to both of interfaces.
Due to WAN1 and WAN2 are belonging same ISP, so that’s why traffic not pass through to correct interface.
You can try to setup correct interface IP address in NAT rules, and try it again.
5 -
You're the best! Specifed external IP as WAN1 IP (instead of 'any'), works like a champ! Is this happening this way because IP's are both from the same block of IP's from ISP?
0
All Replies
-
Hi @jwladd
The NAT rule seems only forwarding the traffic from specific WAN interface which you configured.
Could you provide configuration to me by private message or take a screenshot of your NAT rules?
0 -
0 -
Have Exch svr & RDS svr on LAN1 accessible by WAN1 IP. Want to use WAN2->LAN2 for credit card terminal only (PCI compliance). If I access WAN2 IP, ports 80, 4085 & 443 all are forwarded to LAN1, even though NAT rules specify WAN1. Btw, all rules/policies setup via GUI, none from CLI.
0 -
I currently have nothing in DMZ... is that what I need to do to stop pfw's (that specify WAN1) from being active when accessing WAN2 IP? My goal is to have no open ports/pfw's incoming on WAN2, so I never saw reason to NAT WAN2 to DMZ. FYI: credit card terminal (requiring PCI compliance scans) is on LAN2.
0 -
Hi @jwladd
In your NAT rule, you did not setup correct IP address in external IP so traffic will forward to both of interfaces.
Due to WAN1 and WAN2 are belonging same ISP, so that’s why traffic not pass through to correct interface.
You can try to setup correct interface IP address in NAT rules, and try it again.
5 -
You're the best! Specifed external IP as WAN1 IP (instead of 'any'), works like a champ! Is this happening this way because IP's are both from the same block of IP's from ISP?
0 -
Hi @jwladd
It is because your NAT rule is setup as “any”.
So both of WAN will “listen” the traffic from ISP.
If there is request from Internet, then will forward traffic to internal server.
0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 153 Nebula Ideas
- 99 Nebula Status and Incidents
- 5.7K Security
- 280 USG FLEX H Series
- 277 Security Ideas
- 1.4K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 42 Wireless Ideas
- 6.4K Consumer Product
- 250 Service & License
- 395 News and Release
- 85 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 75 Security Highlight