Help with NAT rules setup - USG40
Comments
-
Hi @ChristianG,
Below is the topology picture, hope you can understand what I mean, if it's not clear, please let me know and I'll try to re-do it.
Requests come to the ISP Router (the "router" is an Ubiquiti AirGrid Antenna), and the DMZ is working. I've changed back to Cyberoam to test it, and the external RDP connections worked again. When I put ZYWALL back on, RDP stopped working from WAN to LAN.
It looks like ZYWALL is not accepting WAN to LAN connections, including the appliance's access itself. I can only access ZYWALL from LAN (HTTP and HTTPS), but from WAN I cannot.0 -
@Josias_MaiaTI ,
Have you tried the example of configuration which I shared with you?
As you mentioned"When I put ZYWALL back on, RDP stopped working from WAN to Lan"~~ You should add NAT rule and create the security policy"(Example)
Moreover, as your description, " I can only access ZYWALL from LAN (HTTP and HTTPS), but from WAN I cannot."~~you need to add the security policy to allow specific IP can access USG.
Create object address for remote client
Security policy
Charlie
0 -
Hello @Zyxel_Charlie
Thanks for the reply.
I've tried the example you sent but still doesn't work. I can't access ZyWALL from WAN and I can't RDP from WAN to my Server1.
In the WAN to ZYWALL rule, the source should be any IP originated from a specific country (in this case Brazil).
Also, I don't know if it's useful, but when I was testing and creating the rules as you've sent in the prints, for some reason, my LAN to WAN traffic is affected. I have a Policy Route that redirects LAN to WAN RDP traffic to route through a specific IP, if I create a Policy Control rule like you've sent, it affects that Policy Route. Below is a print for my Policy Routes, I don't know if this is affecting my WAN to LAN access rules.
0 -
@Josias_MaiaTI
All routing rules are for outgoing traffic will not affect the RDP service.
To analyze this case, I want to confirm information with you.
1. Please disable the firewall and see can you access the zywall?
2. Do you change the access port to 4433? If so, please add the security rule: Wan->Zywall, Service: 4433(you need to create the Service first)
3. Do you want the RDP Service from Port 41000 (Wan)to 3389(Lan)? (I read your original post was port 42000, but the picture you share display 41000)
Charlie0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 151 Nebula Ideas
- 98 Nebula Status and Incidents
- 5.7K Security
- 276 USG FLEX H Series
- 276 Security Ideas
- 1.4K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 42 Wireless Ideas
- 6.4K Consumer Product
- 250 Service & License
- 395 News and Release
- 85 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 74 Security Highlight