How to check the NAT rule using CLI for USG Flex H series models?

Zyxel_Jeff
Zyxel_Jeff Posts: 1,169  Zyxel Employee
Third Anniversary 100 Answers 500 Comments Friend Collector
edited June 14 in Networking

Scenario :

Users usually create NAT rules via the Web-GUI (as shown below). While troubleshooting NAT-related issues, users may use the CLI mode. This guide will show you how to check the NAT rules in CLI mode.

Answer :

Please enter the CLI command "show config vrf main virtual-server rule" to check the current NAT rules on the firewall, as shown below:

usgflex100h> show config vrf main virtual-server rule
rule NAT
enabled true
interface ge1
source-ip any
original-ip address 10.214.48.40
map-to address 192.168.168.168
nat-1-1-map
false
..
nat-loopback
true
..
map-type port protocol any original-port 55 mapped-port 66


Don't miss this great chance to upgrade your Nebula org. for free! https://bit.ly/4g2pS9L

Tagged: