NAT with original destination option

Posts: 6  Freshman Member
First Comment
edited April 2021 in Security
Hello,

i have a question about NAT in a ZyWall device (USG210). I need to NAT traffic from DMZ (192.168.1.2) to LAN (172.16.48.2) for a specific port (tcp/1352), but only if original destination matches 10.0.1.2 (a device behind wan interface).

How to achieve?

Hint: with netfilter, I can achieve this by following rule:
iptables -A PREROUTING -i dmz -d 10.0.1.2 -p tcp -m tcp --dport 1352 -j DNAT --to-destination 172.16.48.2

Thank you.

Regards, Radim.




Comments

  • Posts: 1,034  Zyxel Employee
    50 Answers 500 Comments Friend Collector Fourth Anniversary
    Hello ITMT,
    You can follow the steps as below.
    Create address object for DMZPC, LanPC and Lan interface.
    Also create Service port 1352.


    Create the SNAT profile on Routing page.

    Charlie

Welcome!

It looks like you're new here. If you want to get involved, click on this button!

Welcome!

It looks like you're new here. If you want to get involved, click on this button!