FLEX500: Match default rule DNAT Packet, DROP

Options
tomeC
tomeC Posts: 4 image  Freshman Member
First Comment Third Anniversary
Hello,

Can anybody explain that type of log like below:?

Match default rule DNAT Packet, DROP  source: 192.168.100.12 --- dest.: 192.168.100.1

I haven't any NAT service to that subnet configured.
I have one NAT rule but destination address is in different subnet (different vlan)

All Replies

  • smb_corp_user
    smb_corp_user Posts: 172 image  Master Member
    5 Answers First Comment Friend Collector Third Anniversary
    https://community.zyxel.com/en/discussion/3993/match-default-rule-dnat-packet-drop

    Not sure how much it helps, but at least it can give you a little bit of insight to what the parts can be. You may also want to review the list of rules to see if any of them affect the NAT behaviour.
  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,568 image  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments
    Hi @tomeC,

    Does your firewall have any interface binding subnet 192.168.100.X/24?
    Moreover, please help to check if there are any physical cable attached between lan and wan switch.
  • tomeC
    tomeC Posts: 4 image  Freshman Member
    First Comment Third Anniversary
    edited December 2022
    1. Yes, interface is in DMZ zone (base port also dmz)
    2. No, there is no physical cable between LAN and WAN

  • tomeC
    tomeC Posts: 4 image  Freshman Member
    First Comment Third Anniversary
    I found that CDR security service is a cause of it. After disabling there is no more problems. Actually that scope (192.168.100.X/24) belongs to vlan which is in Qarantine VLAN ID in CDR settings, but I cant remove it - can't set it to "none"?

    Can anybody explain this behaviour?

  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,568 image  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments
    Hi @tomeC,

    Can you send me startup configuration in pm for further checking. 
    Thanks.