Zywall keeps blocking my server outgoing traffic

vfm_IT
vfm_IT Posts: 13  Freshman Member
First Anniversary Friend Collector First Comment
edited April 2021 in Security

I have a server IP:192.168.20.2 in LAN1

Zywall USG110 (Version V4.33(AAPH.0)) keeps block outgoing traffic from that server.

All other PCs on LAN1 don´t have this issue.

I even created a security policy to allow outgoing traffic from my server and I gave that policy priority #1. but It bypass that policy.

I am sharing Log, Policy security and some more.

Please help me.


Accepted Solution

All Replies

  • PeterUK
    PeterUK Posts: 2,702  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer

    Most odd is the gateway for LAN1 192.168.20.1 subnet 255.255.255.0?

    Is their anything more in the logs that might help without the filter?

    Have you made a routing rule from LAN1 to next hop WAN1 by SNAT?

  • imaohw
    imaohw Posts: 123  Ally Member
    First Anniversary 10 Comments Friend Collector First Answer

    Are you sure the server is on Lan1?

  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,444  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer

    Hi @vfm_IT

    Can you post the following CLI result for checking.

    Router> show zone user-define

    Router> show zone system-default

  • vfm_IT
    vfm_IT Posts: 13  Freshman Member
    First Anniversary Friend Collector First Comment

    @PeterUK

    Your comment was a great help for me.

    But I can not figure out why the zyxel consider my server 192.168.20.2 is member of LAN2 (see attachment)


    While my LAN1 is 192.168.20.X/255.255.255.0 and my LAN2 is 191.168.X.X/255.255.0.0 (see attachment as a proof)


    I have to create a specific policy rule to make the zyxel allow outgoing access for my server 192.168.20.2 (see attachment as a proof)


    Can someone explain why? is this a bug on the zyxel router?

  • vfm_IT
    vfm_IT Posts: 13  Freshman Member
    First Anniversary Friend Collector First Comment

    @Zyxel_Cooldia

    Hello

    Please find print screen attached


  • PeterUK
    PeterUK Posts: 2,702  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer

    What port is the server connected too on the USG110?

    How has port role setup?

  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,444  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer

    Hi @vfm_IT

    It seems host 192.168.20.2 goes to wrong interface.

    Can you get the CLI “show arp-table” to check where the host 192.168.20.2 come from? 


    Show arp table


  • vfm_IT
    vfm_IT Posts: 13  Freshman Member
    First Anniversary Friend Collector First Comment

    @PeterUK

    Thanks for your help.

    I have been able to identify the issue and fix it.

    My server was connected on LAN2 and that´s why the USG was blocking outgoing traffic from my server.

Security Highlight