Where the PAT (Port Address Translation) can be configured
All Replies
-
Hi @mipecAG
Theoretically, USG will dynamically assign the port which is unoccupied when doing NAPT behavior. And we can’t configure a specific range to dynamic ports.
According to your situation, there are some points we need to clarify:
(1). What USG model and firmware version you are using now?
(2). Does this phenomenon appear often?
(3). What kind of action of host lead to this phenomenon?
(4). If the dynamic port change to 1040 or 10xx for a while, will it change to the higher range 49152 ..65535 again?
You can refer to the following link tutorial use USB to log traffic syslog.
That will help you to check your dynamic port number of historical traffic.
https://community.zyxel.com/en/discussion/4134/log-and-backup-to-usb
select Network category.
The traffic log will be logged.
Thanks.Don't miss this great chance to upgrade your Nebula org. for free! https://bit.ly/4g2pS9L
0 -
Are you telling about the source port for outgoing connections? The USG will try not to change the source port when sending out the WAN.
Your ISP might be changing the source port?
If you do a packet capture in the USG for LAN and WAN load up some pages then compare the source port before and after NAT.
0
Categories
- All Categories
- 414 Beta Program
- 2.2K Nebula
- 131 Nebula Ideas
- 91 Nebula Status and Incidents
- 5.4K Security
- 178 USG FLEX H Series
- 258 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1K Wireless
- 36 Wireless Ideas
- 6.2K Consumer Product
- 236 Service & License
- 372 News and Release
- 79 Security Advisories
- 24 Education Center
- 5 [Campaign] Zyxel Network Detective
- 2.9K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 80 About Community
- 69 Security Highlight