Unable to open port /NAT on USG40W
Options
I have followed both of these guide to a "T" and my USG40W refuses to port forward:
https://mysupport.zyxel.com/hc/en-us/articles/360003880919--ZyWALL-USG-
How-to-open-ports-on-a-ZyWALL-USG-router-Port-Forwarding-NAT-
https://support.zyxel.eu/hc/en-us/articles/360001390934-NAT-Rule-Configuration-on-a-USG-Port-Forwarding-
I have checked and rechecked my objects and ports, but nothing seems to work in the logs I can see that traffic from expected IPs is trying to connect in because I get the following message:
There is definitely a policy at priority one that allows the appropriate service. What am i doing wrong here?
https://mysupport.zyxel.com/hc/en-us/articles/360003880919--ZyWALL-USG-
How-to-open-ports-on-a-ZyWALL-USG-router-Port-Forwarding-NAT-
https://support.zyxel.eu/hc/en-us/articles/360001390934-NAT-Rule-Configuration-on-a-USG-Port-Forwarding-
I have checked and rechecked my objects and ports, but nothing seems to work in the logs I can see that traffic from expected IPs is trying to connect in because I get the following message:
notice | Security Policy Control | Match default rule, DROP [count=22] |
There is definitely a policy at priority one that allows the appropriate service. What am i doing wrong here?
0
Accepted Solution
-
Check the port role and port you are connected too
0
All Replies
-
NAT instruct your device about how manage the packages.
Then security policy allows the traffic.
If you will publish (even masked/with data replaced) both NAT and Security policies i could analyze it and make my suggestions.0 -
In the NAT rule have you left "source IP" to any?0
-
Yes, source IP is set to any.

0 -
Yes I am familiar on this concept and I am pretty sure its configured correctlymMontana said:NAT instruct your device about how manage the packages.
Then security policy allows the traffic.
If you will publish (even masked/with data replaced) both NAT and Security policies i could analyze it and make my suggestions.
NAT:
Security policy:
Preview
0 -
Check the port role and port you are connected too
0 -
In config > network > interface that the device is connected to the port for Lan2
0
Categories
- All Categories
- 442 Beta Program
- 2.9K Nebula
- 219 Nebula Ideas
- 127 Nebula Status and Incidents
- 6.5K Security
- 588 USG FLEX H Series
- 344 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.4K Wireless
- 52 Wireless Ideas
- 7K Consumer Product
- 298 Service & License
- 476 News and Release
- 91 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.8K FAQ
- 34 Documents
- 87 About Community
- 102 Security Highlight
Freshman Member
Guru Member