USG20W-VPN - Where is the one-to-many NAT rule?

Options
pauloamgcosta
pauloamgcosta image  Freshman Member
First Comment Friend Collector

Hello community;

I've setup this firewall as a trivial home router, allocating all ports to the same interface and using them as a switch, and the WAN port connected to my ISP. Straightforward and no hassles but I noticed that I couldn't find any NAT or firewall rule that would allow my LAN to access the internet despite being able to do so.

I've looked under 'configuration → netwotk → NAT' and 'configuration → security policy → policy control' as the most likely places to hold such rule but didn't find any. Looked at all options afterwards but still didn't find it.

Exporting running-config and peeking into it also led me nowhere.

Am I missing something or is this rule sort of hardcoded and not configurable?
Running firmware V5.43(ABAR.0)


Paulo

Accepted Solution

  • Zyxel_Melen
    Zyxel_Melen image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Answer ✓
    Options

    Hi @pauloamgcosta

    I assume what you mean is SNAT the internal subnet to external interface/WAN IP.

    The Zyxel Device automatically uses SNAT for traffic it routes from internal interfaces to
    external interfaces, which is in Configuration > Network > Interface > Trunk > Default WAN Trunk > Advance > "Enable Default SNAT".

    image.png

    Additionally, if you disable this function, you will need to setup routing policy and SNAT setting by yourself.

    Zyxel Melen


All Replies

  • Zyxel_Melen
    Zyxel_Melen image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Answer ✓
    Options

    Hi @pauloamgcosta

    I assume what you mean is SNAT the internal subnet to external interface/WAN IP.

    The Zyxel Device automatically uses SNAT for traffic it routes from internal interfaces to
    external interfaces, which is in Configuration > Network > Interface > Trunk > Default WAN Trunk > Advance > "Enable Default SNAT".

    image.png

    Additionally, if you disable this function, you will need to setup routing policy and SNAT setting by yourself.

    Zyxel Melen