How to configure NAT on USG FLEX H on Nebula?

Zyxel_Cooldia
Zyxel_Cooldia Posts: 1,520  Zyxel Employee
Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments
edited April 11 in Networking

Here is an example of allowing access to the internal server behind USGFLEX H device with network address translation (NAT). Internet users can access the server directly by it's public IP address and a NAT rule will forward traffic from the internet to the local server in the intranet.

image-3383fd12935a1-a07f.jpeg

Here is an example that the internet users would like to access the HTTP File Server behind the USG FLEX H

Configuration

Go to “Site-wide > Configure > Firewall > NAT”, and click "Add" to create a NAT rule.

- Input the rule name : Web_Server

- select Virtual Server

- Incoming Interface: ge1

- Configure the Source IP to limit the access by the Source IP. You may select Any

- Configure the External IP. Select Custom and type IP 10.214.48.46, which is the IP address of the wan interface valid IP.

- Configure the internal IP. Select Custom and type IP192.168.168.33, which is the IP address of the internal server.

- Port Mapping Type: Select HTTP for both external and internal service. 

1744104028105.jpg

Go to “Site-wide > Configure > Firewall > Security policy” to create a policy to allow http tcp 80 port access from Wan to Lan.

1744107899953.jpg

Verification

Type http://10.214.48.46 into the browser, and it display the HTTP service page.