Forwarding ports with intermediate router

Options
Enrique_C
Enrique_C Posts: 7 image  Freshman Member
First Comment Second Anniversary
edited October 2023 in Security

Hello, our scenario is:

Internet —— Router (192.168.0.1) —— (192.168.0.2) Zywall USG20 (192.168.9.1) ———- PC (192.168.9.100)

In our router we have create a forwarding rule - all external traffic by 1433 port is redirected to the Firewall wan_IP 192.168.0.2

We need to redirect all the external traffic through 1433 TCP port to PC. Can you help us to configure the firewall-side?

Thanks in advance

All Replies

  • PeterUK
    PeterUK Posts: 4,523 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited October 2023
    Options

    If the 1st router has static route you can do a more advanced way of forwarding.

    Or to double NAT make NAT rule for Virtual Server

    incoming WAN of USG20

    External 192.168.0.2

    internal 192.168.9.100

    port TCP 1433

    Then a firewall rule from WAN to LAN for that port

  • Enrique_C
    Enrique_C Posts: 7 image  Freshman Member
    First Comment Second Anniversary
    Options

    Thank you, we have created a NAT Rule …

    image.png

    External IP - 192.168.0.2

    Internal IP - 192.168.9.100

    And create a Policy …

    image.png

    But cotinues closed …

    image.png

    Thank you

  • PeterUK
    PeterUK Posts: 4,523 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    Options

    Your firewall Policy is wrong needs to be the zone your server is on like LAN1 not Zywall

  • Zyxel_Kevin
    Zyxel_Kevin Posts: 988 image  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 500 Comments
    Options

    Hi @Enrique_C ,

    Greeting Forum , thank PeterUK.

    Please kindly change your zone where internal server located. (not zywall)

    Thank you

  • Enrique_C
    Enrique_C Posts: 7 image  Freshman Member
    First Comment Second Anniversary
    Options

    Hi PeterUK,

    We changed to LAN1

    image.png


    But it continues blocked

    Thank you

  • Zyxel_Kevin
    Zyxel_Kevin Posts: 988 image  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 500 Comments
    Options

    Hi @Enrique_C ,

    Please kindly provide your config by Private Message.

    I will check the configuration.

    Thank you

  • PeterUK
    PeterUK Posts: 4,523 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    Options

    Does your ISP allow port 1433 ?