Unable to open port /NAT on USG40W
I have followed both of these guide to a "T" and my USG40W refuses to port forward:
https://mysupport.zyxel.com/hc/en-us/articles/360003880919--ZyWALL-USG-
How-to-open-ports-on-a-ZyWALL-USG-router-Port-Forwarding-NAT-
https://support.zyxel.eu/hc/en-us/articles/360001390934-NAT-Rule-Configuration-on-a-USG-Port-Forwarding-
I have checked and rechecked my objects and ports, but nothing seems to work in the logs I can see that traffic from expected IPs is trying to connect in because I get the following message:
There is definitely a policy at priority one that allows the appropriate service. What am i doing wrong here?
https://mysupport.zyxel.com/hc/en-us/articles/360003880919--ZyWALL-USG-
How-to-open-ports-on-a-ZyWALL-USG-router-Port-Forwarding-NAT-
https://support.zyxel.eu/hc/en-us/articles/360001390934-NAT-Rule-Configuration-on-a-USG-Port-Forwarding-
I have checked and rechecked my objects and ports, but nothing seems to work in the logs I can see that traffic from expected IPs is trying to connect in because I get the following message:
notice | Security Policy Control | Match default rule, DROP [count=22] |
There is definitely a policy at priority one that allows the appropriate service. What am i doing wrong here?
0
Accepted Solution
-
Check the port role and port you are connected too
0
All Replies
-
NAT instruct your device about how manage the packages.
Then security policy allows the traffic.
If you will publish (even masked/with data replaced) both NAT and Security policies i could analyze it and make my suggestions.0 -
In the NAT rule have you left "source IP" to any?0
-
Yes, source IP is set to any.

0 -
Yes I am familiar on this concept and I am pretty sure its configured correctlymMontana said:NAT instruct your device about how manage the packages.
Then security policy allows the traffic.
If you will publish (even masked/with data replaced) both NAT and Security policies i could analyze it and make my suggestions.
NAT:
Security policy:
Preview
0 -
In config > network > interface that the device is connected to the port for Lan2
0
Categories
- All Categories
- 164 Beta Program
- 1.7K Nebula
- 86 Nebula Ideas
- 62 Nebula Status and Incidents
- 4.7K Security
- 236 Security Ideas
- 1.1K Switch
- 50 Switch Ideas
- 908 WirelessLAN
- 27 WLAN Ideas
- 5.3K Consumer Product
- 172 Service & License
- 294 News and Release
- 65 Security Advisories
- 14 Education Center
- 911 FAQ
- 399 Nebula FAQ
- 249 Security FAQ
- 90 Switch FAQ
- 100 WirelessLAN FAQ
- 18 Consumer Product FAQ
- 55 Service & License FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 68 About Community
- 51 Security Highlight
Guru Member