SNAT public IP

Options
Pas7o
Pas7o Posts: 12 image  Freshman Member
First Comment Friend Collector Fifth Anniversary

I have a zyxel usgflex 700 firewall connected in the cloud nebula.

2 wan interfaces are configured with two different public IPs.

Wan 1 has public IP 1.1.1.1

Wan 2 has public IP 2.2.2.2

Wan 1 is configured as primary, while wan 2 is configured as backup.

To ensure the use of IP continuity, the provider told me that I need to create a rule in the outgoing Source NAT for IP Continuity towards IP 3.3.3.3/32.

How should I do it?

Thanks.

All Replies

  • PeterUK
    PeterUK Posts: 4,542 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited July 2
    Options

    Your ISP does not make it clear what they want you to do.

    Are the public IP WAN1 and WAN2 from the same ISP?

    Are you seeing your WAN IPs by what my IP sites?

    unless they mean to setup fail over to ping the IP 3.3.3.3?

  • Pas7o
    Pas7o Posts: 12 image  Freshman Member
    First Comment Friend Collector Fifth Anniversary
    Options

    Are the public IP WAN1 and WAN2 from the same ISP?
    Yes, they are.

    Are you seeing your WAN IPs by what my IP sites?
    No, I see my WAN IPs in Nebula —> Configure —> Firewall —> Interface

    unless they mean to setup fail over to ping the IP 3.3.3.3?
    In the service that the provider offers there is also IP continuity.
    That is, it is a network technology that maintains the same public IP address even when changing the access network.
    This is because, as I explained before, WAN1 (IP: 1.1.1.1) is the primary. While WAN2 (IP: 2.2.2.2) is backup and only comes into operation if WAN1 is down.
    The IP for the IP Continuity service is another one different from those of the two WANs (IP: 3.3.3.3).
    They told me that I need to create a SNAT rule so that the public IP of the 2 WANs (1.1.1.1 and 2.2.2.2) when a user sees the IP via sites like myip, it shows the IP continuity (3.3.3.3)

  • PeterUK
    PeterUK Posts: 4,542 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    Options

    Are you getting internet now by WAN1  or WAN2?

    You say they are  public IP's not 10. , 192.168. , 172.16

    so what the deal with 3.3.3.3 if you have two public IP's?

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,895 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    edited July 6
    Options

    Hi @Pas7o

    Edit:

    I assume your device is not H series device.

    Nebula management mode doesn't support SNAT setting. If you need to set SNAT setting, please remove your device from your organization and apply Nebula Monitor Mode. In Nebula monitor mode, you can have on-premises configuration GUI and monitor device's status on Nebula. To setup SNAT, please reference this FAQ [ATP/FLEX] Policy route for SNAT.

    Other reference FAQ:

    How to Remove Your Device from Nebula and Administer It Locally

    [ATP/FLEX] How to set up Nebula Monitor Mode? — Zyxel Community

    Below is for DNAT requirement:

    Please set the 3.3.3.3 (I know this is not a real public IP, please correctly enter your public IP) to NAT setting public IP column. Our system will bing this IP to the outgoing interface.

    image.png

    Hope this helps.

    Zyxel Melen


Nebula Tips & Tricks