Opening Ports for external access on ZyWall USG20W
Comments
-
your ZyWALL wan1 IP address is a private (RFC1918) address. Is the ZyWALL behind another router which is also doing NAT?
1 -
Your WAN IP is not set to 83.209.29.154 its 172.16.0.168 going by your NAT rule so your behind another router? Can it be changed to modem mode or bridge mode? Or your ISP blocks you from forwarding ports?
1 -
Hi @PerA,
If there are double/multiple NAT in your topology, you need to configure NAT and firewall rules on not only USG20W but also the routers which are placed ahead of USG20W.
You can follow the guide in the following discussion thread.
See how you've made an impact in Zyxel Community this year!
https://bit.ly/Your2024Moments_Community1 -
Hi,No - it is my ISP directly into the USG20W and behind it I have a LAN1 and a LAN2. Looking at some cases at YouTube there seems to be many suggested ways to configure that and I have to admit that I get lost.If I do it in the following sequence I see step 1, 2 and 3 as understandable:Step 1 - I define a service rule named AVH that is TCP and port 8080Step 2 - I define an address object for the AVH where TYPE is HOST and I use the fixed IP address 192.168.0.10Step 3 - add a FW rule stating from WAN and to LAN1 (where the system 192.168.0.10 is). Source ANY, destination AVH and service AVHThe comes the tricky thing where I loost contrul/understanding and that is the NAT rule where I cant select WAN as incoming interface - only WAN1...I set original IP as ANY, mapped IP as defined AVH, and then port mapping type SERVICE with both following defined av AVHPLEASE NOTE - I have changed so the outbound port from mobile device now is 8080 exactly as the port I want to access on AVH - PLEASE NOTEAny suggestions welcome/Per-ArnePS - my ISP states that they block no ports at all - DS
0 -
Zyxel_Emily said:
Hi @PerA,
If there are double/multiple NAT in your topology, you need to configure NAT and firewall rules on not only USG20W but also the routers which are placed ahead of USG20W.
You can follow the guide in the following discussion thread.
Hi,No - it is my ISP directly into the USG20W and behind it I have a LAN1 and a LAN2. Looking at some cases at YouTube there seems to be many suggested ways to configure that and I have to admit that I get lost.If I do it in the following sequence I see step 1, 2 and 3 as understandable:Step 1 - I define a service rule named AVH that is TCP and port 8080Step 2 - I define an address object for the AVH where TYPE is HOST and I use the fixed IP address 192.168.0.10Step 3 - add a FW rule stating from WAN and to LAN1 (where the system 192.168.0.10 is). Source ANY, destination AVH and service AVHThe comes the tricky thing where I loost contrul/understanding and that is the NAT rule where I cant select WAN as incoming interface - only WAN1...I set original IP as ANY, mapped IP as defined AVH, and then port mapping type SERVICE with both following defined av AVHPLEASE NOTE - I have changed so the outbound port from mobile device now is 8080 exactly as the port I want to access on AVH - PLEASE NOTEAny suggestions welcome/Per-ArnePS - my ISP states that they block no ports at all - DS
0 -
Sorry but No you have another router upstream from the USG20W if you was directly connected your WAN1 on the USG20W would show 83.209.29.154 which it does not and shows 172.16.0.168
0 -
Hi @PerA,
"it is my ISP directly into the USG20W and behind it I have a LAN1 and a LAN2."
Could you share the topology with us?
For example, is there a xDSL router provided by the ISP?
ISP----xDSL router------(wan)USG20W
Please confirm with ISP if they provide public IP address to you.
In your screen shot, wan1 is 172.16.0.168 which is private IP address.
If the ISP gives you private IP address, or there is a xDSL router in your topology, you need to configure firewall rule or NAT rule on the router if it is allowed for configuration.
See how you've made an impact in Zyxel Community this year!
https://bit.ly/Your2024Moments_Community0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 152 Nebula Ideas
- 100 Nebula Status and Incidents
- 5.8K Security
- 290 USG FLEX H Series
- 278 Security Ideas
- 1.5K Switch
- 77 Switch Ideas
- 1.1K Wireless
- 42 Wireless Ideas
- 6.5K Consumer Product
- 252 Service & License
- 396 News and Release
- 85 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 86 About Community
- 75 Security Highlight