How to create DMZ on NSG?
Zyxel_Melen
Posts: 2,403 Zyxel Employee
A DMZ (Demilitarized Zone) is a concept in your network to create a public area where you can place public servers for external network access. The typical rule is to allow traffic from both the WAN and LAN, but not to allow traffic from the DMZ to the LAN. This helps prevent external attackers from using it as a stepping stone to affect the security of important internal devices.
Nebula does not have a DMZ option for security gateway. However, you can use guest interface and NAT rule to create a DMZ.
NSG 200 is used as an example in this FAQ.
Configuration step:
- Navigate to the interface page and assign a port to port group 2.
- Configure LAN 2 as port group 2 and the interface settings.
- To make LAN 2 as a DMZ, please enable the guest interface function.
- Create a NAT rule for your server under DMZ. Path: Security gateway > Firewall
https://community.zyxel.com/en/discussion/11998
You can reference these FAQs to set the virtual server rule:
Verify:
Client: 192.168.11.33 ( LAN 1 )
Server: 192.168.13.11 ( DMZ / LAN 2 )
- LAN 1 client can ping to DMZ server.
- DMZ server cannot ping to LAN 1 client.
0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 144 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.6K Security
- 237 USG FLEX H Series
- 267 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.3K Consumer Product
- 246 Service & License
- 383 News and Release
- 83 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.2K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight