Forwarding ports with intermediate router

Options
Enrique_C
Enrique_C Posts: 7
First Anniversary First Comment
edited October 2023 in Security

Hello, our scenario is:

Internet —— Router (192.168.0.1) —— (192.168.0.2) Zywall USG20 (192.168.9.1) ———- PC (192.168.9.100)

In our router we have create a forwarding rule - all external traffic by 1433 port is redirected to the Firewall wan_IP 192.168.0.2

We need to redirect all the external traffic through 1433 TCP port to PC. Can you help us to configure the firewall-side?

Thanks in advance

All Replies

  • PeterUK
    PeterUK Posts: 2,878  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    edited October 2023
    Options

    If the 1st router has static route you can do a more advanced way of forwarding.

    Or to double NAT make NAT rule for Virtual Server

    incoming WAN of USG20

    External 192.168.0.2

    internal 192.168.9.100

    port TCP 1433

    Then a firewall rule from WAN to LAN for that port

  • Enrique_C
    Options

    Thank you, we have created a NAT Rule …

    External IP - 192.168.0.2

    Internal IP - 192.168.9.100

    And create a Policy …

    But cotinues closed …

    Thank you

  • PeterUK
    PeterUK Posts: 2,878  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    Your firewall Policy is wrong needs to be the zone your server is on like LAN1 not Zywall

  • Zyxel_Kevin
    Zyxel_Kevin Posts: 803  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    Hi @Enrique_C ,

    Greeting Forum , thank PeterUK.

    Please kindly change your zone where internal server located. (not zywall)

    Thank you

  • Enrique_C
    Options

    Hi PeterUK,

    We changed to LAN1


    But it continues blocked

    Thank you

  • Zyxel_Kevin
    Zyxel_Kevin Posts: 803  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    Hi @Enrique_C ,

    Please kindly provide your config by Private Message.

    I will check the configuration.

    Thank you

  • PeterUK
    PeterUK Posts: 2,878  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    Does your ISP allow port 1433 ?

Security Highlight