Zywall 310 can not reach public dns itself System/DNS??

KMPKMP Member Posts: 15  Freshman Member
Hi we have a Zywall 310 running the latest firmware 4.62(AAAB.0)

The device itself can not reach public internet, for example i would like to upgrade the security IDP services, but it seems the device can not reacht the license server (portal.zyxel.com)

I have tried setting de System/DNS settings to and tried without. 

When running diagnostics and opening nslookupv4 it won't reach dns servers.

What could be the problem? Our infrastructure behind the Zywall will reach internet fine. No problems.

All Replies

  • PeterUKPeterUK Member Posts: 811  Guru Member
    edited February 20, 2021 11:36PM

    Do you have a external interface to the internet?

    do you have a bridge setup?

    From the Zywall diagnostics use TRACEROUTE IPv4 to and see what you get.

  • KMPKMP Member Posts: 15  Freshman Member
    Hi PeterUK,

    Yes, an external interface is connected: ISP Fiber -> BaseT switch.
    IPoE setup on WAN2 interface of Zywall with fixed IP.

    A traceroute. It seems it does route via the ISP gateway. Then at hob 30 it stops.

  • KMPKMP Member Posts: 15  Freshman Member
    No Bridge setup.
  • PeterUKPeterUK Member Posts: 811  Guru Member
    edited February 22, 2021 5:48AM

    So do you SNAT on a single WAN IP or do you have a subnet of WAN IP's?

  • KMPKMP Member Posts: 15  Freshman Member
    Hi, Yes we do SNAT on multiple WAN IP's. Using policy route

  • PeterUKPeterUK Member Posts: 811  Guru Member

    But have you tried SNAT the WAN IP the interface is on not your other WAN IP's by outgoing-interface ? I think the issue is you can't use that IP for internet and the Zywall is trying that IP and fails.

    My setup has some what the same problem but different so what I think might work is if you make another port external zone OPT with a IP of the of your LAN subnet to its gateway connect it to your switch for that LAN so that it becomes a client and SNAT out your set WAN IP then setup a trunk with that interface at the top. If this works like I hope the Zywall will use that interface to make connections for DNS and such.

  • Zyxel_JeffZyxel_Jeff Zyxel Offical Agent Posts: 130  mod

    Hi @KMP

    Could you provide your startup-config file to us for further investigation?


  • KMPKMP Member Posts: 15  Freshman Member
    Hi Jeff, I have provided you the conf file in a pm. 

Sign In to comment.