[USG Flex H] - Multiple NAT rule for different interface

Options
2»

All Replies

  • Zyxel_Judy
    Zyxel_Judy image  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security Zyxel Certified Network Engineer Level 1 - Nebula
    Answer ✓
    Options

    Hi @Maverick87 ,

    That's exactly the right way to solve this — what you've built is the standard "split-horizon DNS + NAT loopback (hairpin NAT)" pattern, and it's a well-supported approach on USG FLEX H (and firewalls generally), not a workaround with hidden downsides.

    Why it works: your DDNS name resolves differently depending on where the query comes from (public IP from WAN, 192.168.0.1 via your internal A record), and the loopback-enabled NAT rule lets internal clients hit the router's "external" address and still get redirected to 192.168.0.1 correctly.

    On safety — this is fine as long as you keep in mind: Check your security policy still enforces the access you intend between zones. Loopback NAT only handles the address translation; if VLANs weren't supposed to reach 192.168.0.1 before, make sure the security policy for that interface still reflects that intent.

    Zyxel_Judy

  • Maverick87
    Maverick87 image  Master Member
    Zyxel Certified Network Administrator - WLAN Zyxel Certified Network Administrator - Nebula Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate
    Options

    Hi @Zyxel_Judy,

    that you for your confirmation. Can you confirm also that in this case, with NAT Loopback, the IP address from hostname is still resolved internally?

    Thank you

  • PeterUK
    PeterUK image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited September 8
    Options

    As long as the client DNS lookups point to Zywall yes