Marco Pagnotelli

Options

Hello everyone,
I have a Zyxel USG60 that needs to connect clients to an external https server (cloud). The server gives me a timeout error. doing the same without firewall I have no errors. I would like to know how I can open a channel to the server's IP address for port 443, maintaining the current firewall rules. Thank you

Accepted Solution

  • smb_corp_user
    smb_corp_user Posts: 161  Master Member
    First Anniversary 10 Comments Friend Collector First Answer
    Answer ✓
    Options

    You most likely need to create an extra WAN-to-LAN Firewall Policy Rule to allow incoming traffic from the external https server. Not sure if reverse rule is needed, since it should be safe to assume that LAN clients do not have restrictions on internet access (please verify, just in case).

    The WAN-to-LAN policy rule can be restricted to single address source, but make sure you know whether there are any other required protocols other than 443/SSL. Target can be subnet (LAN).

All Replies

  • smb_corp_user
    smb_corp_user Posts: 161  Master Member
    First Anniversary 10 Comments Friend Collector First Answer
    Answer ✓
    Options

    You most likely need to create an extra WAN-to-LAN Firewall Policy Rule to allow incoming traffic from the external https server. Not sure if reverse rule is needed, since it should be safe to assume that LAN clients do not have restrictions on internet access (please verify, just in case).

    The WAN-to-LAN policy rule can be restricted to single address source, but make sure you know whether there are any other required protocols other than 443/SSL. Target can be subnet (LAN).

  • marcomultitec
    Options

    Thanks a lot! I'll try to do this.

Security Highlight