no default SNAT usg310 himself
Hello
I have USG310 V4.73
my wan2 has a virtual ip wan2:1 (IP:AA.BB.CC.DD)
with ssh I have to add snat to ping internet( ping 8.8.8.8 source AA.BB.CC.DD )but
how can I add the virual IP in the default snat for the router himself.??
Now I can not update time, update firmware from cloud ect ect
thx in adv
All Replies
-
HI @Chakib ,
By default, outgoing traffic only translate soruce address to "interface IP".
If you would use virtual IP wan2:1 for SNAT. Please kindly use Policy Route and set "Souce Network Address Translation" to wan2:1 address.
Please feel free to contact us if any concerns. Thank you
Kevin
0 -
Hi Kevin
Thx for your prompt reply.
I use Already policy route for the LAN the SNAT with the viruals IP.( no problem)My question is regarding the UTM himsel (USG310) can not go to the internet to update time for exp.
brgds
0 -
Do you have a WAN subnet? You should not need virtual ip to SNAT on another WAN IP.
…think I get your problem now…hmmm…so you have on WAN2 a IP that has no internet that you get your WAN routed too you that you SNAT…but how to get Zywall to have internet….
I don't have the same problem as your exactly but in a round about way it is the same how I solved it was another USG with a VLAN that each other SNAT to get internet.
due to x2 real DMZ on the same IP
0 -
Hi @Chakib ,
I set WAN as private IP which cannot access internet. WAN1:1 as IP can access internet.
It can ping 8.8.8.8 itself.
Please kindly share your config file by private message. I will do the verify.
Thank you
0 -
@Zyxel_Kevin
Are you sure 10. dose not have Internet access? if you do a packet capture ping is by 100.?
0 -
I am sorry. 100.100.100.0/24 is a subset I created for testing. It cannot access internet.
10.214 is behind NAT router. It can access internet.
0 -
yes thats the point of the OP problem is 10. can not access internet by ISP and I see no easy way round this with just one USG
0 -
Dear Kein,
sorry for my lare reply
Pls pic attached .
Well I resolved this problem Iadding Wan1 via ISP with ADSL .
I sent you also two pings before to add wan1 with snat and without.
B/rgds
0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 151 Nebula Ideas
- 100 Nebula Status and Incidents
- 5.7K Security
- 281 USG FLEX H Series
- 278 Security Ideas
- 1.5K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 42 Wireless Ideas
- 6.5K Consumer Product
- 251 Service & License
- 396 News and Release
- 85 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 86 About Community
- 75 Security Highlight