[USG Flex H] - Block rule to broadcast IP
Master Member
Hello everyone,
I've an IoT device (on 192.168.0.0/24 LAN) that needs to communicate with the broadcast IP (192.168.0.255) on port 59387, but seems that the rule are blocked.
Why? What I'm wrong?
What is the rule that I need to add to unblock it?
Thank you
Accepted Solution
-
Hi @Maverick87 ,
We need to have these kinds of logs appear because it shows the traffic hits the Policy Control rule "Deny Any to Any" (the last/default policy), which applies to traffic in both the LAN and WAN directions.
In case you don't want to have the block logs from LAN to broadcast IP, you can add a policy (LAN → Broadcast) with logging disabled before the last implicit default deny policy to achieve the desired filtering. The steps as below:
- Navigate to Security Policy > Policy Control in the Web GUI.
- Create a new policy rule positioned near the bottom of your rule list (directly above the implicit default-deny rule).
- Set the parameters as follows:
- Source: Any (or the specific local zones/subnets, e.g., LAN)
- Destination: Create and select an address object for the broadcast address
- Action: Deny/ Reject
- Log: No Log
4. Save the rule.
Zyxel_Judy
0
All Replies
-
A broadcast for like UDP to the USG will Always (from what I can tell) be blocked so you have like
LAN IP/subnet 192.168.0.0/24
a switch to USG with devices at 192.168.0.31 and 192.168.0.100
when a broadcast happens from like 192.168.0.31 the switch on the same VLAN broadcast to all ports which 192.168.0.100 will see but also the USG at like 192.168.0.1I guess really the USG could filter these broadcast out to not show in the logs
0 -
Hi @PeterUK,
Thank you, so is not an "error", the communication is not really blocked and I can ignore it?
Thank you
0 -
yes you can ignore it
0 -
Hi @PeterUK,
I've opened an Idea to hide/remove this entry log (writes uselessly inside the log, taking up space for other more interesting logs).0 -
Hi @Maverick87 ,
We need to have these kinds of logs appear because it shows the traffic hits the Policy Control rule "Deny Any to Any" (the last/default policy), which applies to traffic in both the LAN and WAN directions.
In case you don't want to have the block logs from LAN to broadcast IP, you can add a policy (LAN → Broadcast) with logging disabled before the last implicit default deny policy to achieve the desired filtering. The steps as below:
- Navigate to Security Policy > Policy Control in the Web GUI.
- Create a new policy rule positioned near the bottom of your rule list (directly above the implicit default-deny rule).
- Set the parameters as follows:
- Source: Any (or the specific local zones/subnets, e.g., LAN)
- Destination: Create and select an address object for the broadcast address
- Action: Deny/ Reject
- Log: No Log
4. Save the rule.
Zyxel_Judy
0 -
Hi @Zyxel_Judy,
Thank youI've created the rule and all works.
One point: the rule needs to be created with To: ZyWall zoneThank you
0
Categories
- All Categories
- 442 Beta Program
- 3K Nebula
- 232 Nebula Ideas
- 131 Nebula Status and Incidents
- 6.7K Security
- 684 USG FLEX H Series
- 362 Security Ideas
- 1.8K Switch
- 87 Switch Ideas
- 1.4K Wireless
- 56 Wireless Ideas
- 7.1K Consumer Product
- 310 Service & License
- 504 News and Release
- 97 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 5.1K FAQ
- 34 Documents
- 89 About Community
- 112 Security Highlight

Zyxel Employee
Guru Member