SNAT public IP
I have a zyxel usgflex 700 firewall connected in the cloud nebula.
2 wan interfaces are configured with two different public IPs.
Wan 1 has public IP 1.1.1.1
Wan 2 has public IP 2.2.2.2
Wan 1 is configured as primary, while wan 2 is configured as backup.
To ensure the use of IP continuity, the provider told me that I need to create a rule in the outgoing Source NAT for IP Continuity towards IP 3.3.3.3/32.
How should I do it?
Thanks.
All Replies
-
Your ISP does not make it clear what they want you to do.
Are the public IP WAN1 and WAN2 from the same ISP?
Are you seeing your WAN IPs by what my IP sites?
unless they mean to setup fail over to ping the IP 3.3.3.3?
0 -
Are the public IP WAN1 and WAN2 from the same ISP?
Yes, they are.Are you seeing your WAN IPs by what my IP sites?
No, I see my WAN IPs in Nebula —> Configure —> Firewall —> Interfaceunless they mean to setup fail over to ping the IP 3.3.3.3?
In the service that the provider offers there is also IP continuity.
That is, it is a network technology that maintains the same public IP address even when changing the access network.
This is because, as I explained before, WAN1 (IP: 1.1.1.1) is the primary. While WAN2 (IP: 2.2.2.2) is backup and only comes into operation if WAN1 is down.
The IP for the IP Continuity service is another one different from those of the two WANs (IP: 3.3.3.3).
They told me that I need to create a SNAT rule so that the public IP of the 2 WANs (1.1.1.1 and 2.2.2.2) when a user sees the IP via sites like myip, it shows the IP continuity (3.3.3.3)0 -
Are you getting internet now by WAN1 or WAN2?
You say they are public IP's not 10. , 192.168. , 172.16
so what the deal with 3.3.3.3 if you have two public IP's?
0 -
Hi @Pas7o
Edit:
I assume your device is not H series device.
Nebula management mode doesn't support SNAT setting. If you need to set SNAT setting, please remove your device from your organization and apply Nebula Monitor Mode. In Nebula monitor mode, you can have on-premises configuration GUI and monitor device's status on Nebula. To setup SNAT, please reference this FAQ [ATP/FLEX] Policy route for SNAT.
Other reference FAQ:
How to Remove Your Device from Nebula and Administer It Locally
[ATP/FLEX] How to set up Nebula Monitor Mode? — Zyxel Community
Below is for DNAT requirement:
Please set the 3.3.3.3 (I know this is not a real public IP, please correctly enter your public IP) to NAT setting public IP column. Our system will bing this IP to the outgoing interface.
Hope this helps.
Zyxel Melen0
Categories
- All Categories
- 442 Beta Program
- 3K Nebula
- 232 Nebula Ideas
- 132 Nebula Status and Incidents
- 6.7K Security
- 691 USG FLEX H Series
- 365 Security Ideas
- 1.8K Switch
- 87 Switch Ideas
- 1.4K Wireless
- 56 Wireless Ideas
- 7.1K Consumer Product
- 312 Service & License
- 505 News and Release
- 97 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 5.1K FAQ
- 34 Documents
- 89 About Community
- 112 Security Highlight
Freshman Member
Guru Member
Zyxel Employee
