user111 Posts: 5  Freshman Member
First Comment

Hello, please help,am newbie,have a USG40 firewall,I would like to run a web server on the DMZ port, how do I have to configure the rules so that the web server can be reached from outside, everything works via Lan1 with port forwarding, I just don't know how it works with DMZ, on the Fritzbox which is the DSL modem they will Ports 80 and 443 forwarded correctly! Thank you !


Accepted Solution

  • Zyxel_Kay
    Zyxel_Kay Posts: 1,280  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - WLAN Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security
    Answer ✓

    Hi @user111

    If you would like to achieve the scenario described above, you can configure a port as a DMZ interface. Then, apply the following rules to the DMZ interface:

    • Traffic from WAN to DMZ: Allowed. This can be achieved using NAT rules.
      Create NAT rules to map the WAN IP address to the server's IP address in the DMZ. If you have several ports that need to be mapped to the server in the DMZ, you will need to create an entry for each port or input a range of ports under Public Ports/Local Ports.
    • Traffic from LAN to DMZ: Allowed. This is achieved by the default security rule.
    • Traffic from DMZ to LAN: Denied. This can be achieved by creating a security rule.


All Replies

  • Zyxel_Kay
    Zyxel_Kay Posts: 1,280  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - WLAN Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security
    Answer ✓

    Hi @user111

    If you would like to achieve the scenario described above, you can configure a port as a DMZ interface. Then, apply the following rules to the DMZ interface:

    • Traffic from WAN to DMZ: Allowed. This can be achieved using NAT rules.
      Create NAT rules to map the WAN IP address to the server's IP address in the DMZ. If you have several ports that need to be mapped to the server in the DMZ, you will need to create an entry for each port or input a range of ports under Public Ports/Local Ports.
    • Traffic from LAN to DMZ: Allowed. This is achieved by the default security rule.
    • Traffic from DMZ to LAN: Denied. This can be achieved by creating a security rule.


  • PeterUK
    PeterUK Posts: 3,645  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    The way simple DMZ works is like any LAN that being you have its own LAN subnet it then have a zone for the firewall policy such that LAN can't go to DMZ or DMZ can't go to LAN but having DMZ go to WAN only or WAN to DMZ.

    Note by default LAN goes to any so you might want to change that.

  • user111
    user111 Posts: 5  Freshman Member
    First Comment

    Thank you very much, I'll try it!
  • user111
    user111 Posts: 5  Freshman Member
    First Comment

    Hello, good morning,worked great, Can you actually create and download a backup so that you can restore it after a firmware update? Can you only create a backup point in easy mode?Thank you very much, have a nice week!😉
  • user111
    user111 Posts: 5  Freshman Member
    First Comment

    Oh well, you can download and upload backups, I found it. Thank you very much!