[USG Flex H] - Multiple NAT rule for different interface
All Replies
-
Hi @Maverick87 ,
That's exactly the right way to solve this — what you've built is the standard "split-horizon DNS + NAT loopback (hairpin NAT)" pattern, and it's a well-supported approach on USG FLEX H (and firewalls generally), not a workaround with hidden downsides.
Why it works: your DDNS name resolves differently depending on where the query comes from (public IP from WAN, 192.168.0.1 via your internal A record), and the loopback-enabled NAT rule lets internal clients hit the router's "external" address and still get redirected to 192.168.0.1 correctly.
On safety — this is fine as long as you keep in mind: Check your security policy still enforces the access you intend between zones. Loopback NAT only handles the address translation; if VLANs weren't supposed to reach 192.168.0.1 before, make sure the security policy for that interface still reflects that intent.
Zyxel_Judy
0 -
Hi @Zyxel_Judy,
that you for your confirmation. Can you confirm also that in this case, with NAT Loopback, the IP address from hostname is still resolved internally?
Thank you
0 -
As long as the client DNS lookups point to Zywall yes
0
Categories
- All Categories
- 442 Beta Program
- 3.1K Nebula
- 237 Nebula Ideas
- 6.8K Security
- 740 USG FLEX H Series
- 376 Security Ideas
- 1.8K Switch
- 87 Switch Ideas
- 1.5K Wireless
- 58 Wireless Ideas
- 7.2K Consumer Product
- 319 Service & License
- 512 News and Release
- 99 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 5.3K FAQ
- 34 Documents
- 91 About Community
- 119 Security Highlight
Zyxel Employee
Master Member
Guru Member