USG 50 - NAT Configuration Issue - Layer 3 Switch behind Zywall.

Options
RCorbin
RCorbin Posts: 1
edited April 2021 in Security
I have a USG 50 Firewall with DMZ port configured with Subnet 172.16.0.1/28.
Connected to the DMZ port, I have a Cisco 3560 Layer3 Switch connected. 
Zywall DMZ (172.16.0.1) --> Cisco 3560 (172.16.0.10).
Cisco 3560 has IP routing Enabled, and a VLAN 100 setup (192.168.100.0/24). (VLAN100 SVI 192.168.100.5) 
GW (ip route) of last resort on the Cisco 3560 is 0.0.0.0 0.0.0.0 172.16.0.1

A PC host (192.168.100.1) is connected to the Cisco. PC Host can ping it's SVI 192.168.100.5 without issue. Cannot ping anything else, not LAN1, LAN2 or external sites. Zywall packet capture shows the DMZ interface receiving a packet from PC host 192.168.100.1 --> 8.8.8.8, but with no response found. 

On the Cisco Switch, I can ping everything, DMZ interface, LAN1, and LAN2 hosts and interfaces and any external site.

On the Zywall I have a static route to the 192.168.100.0 subnet via the DMZ interface. I can ping into the LAN attached to the CISCO (192.168.100.0) from hosts in the LAN1, LAN2. 

I'm fairly certain the issue is related to NAT. I'm having issues translating a subnet behind the DMZ interface and I am not sure of the configuration on the Zywall USG 50. 

To test this, I set up another router with a layer 2 switch and a Cisco 1841 in a router on a stick configuration and setup NAT on the 1841 to translate from the 192.168.100.0 subnet to the outgoing interface that's connected to the Zywall DMZ port. Traffic flows fine in this scenario. 

If you need additional info, I am happy to provide it. 

Security Highlight