Zywall keeps blocking my server outgoing traffic

vfm_IT
vfm_IT Posts: 13  Freshman Member
First Comment Friend Collector Fourth Anniversary
edited April 2021 in Security

I have a server IP:192.168.20.2 in LAN1

Zywall USG110 (Version V4.33(AAPH.0)) keeps block outgoing traffic from that server.

All other PCs on LAN1 don´t have this issue.

I even created a security policy to allow outgoing traffic from my server and I gave that policy priority #1. but It bypass that policy.

I am sharing Log, Policy security and some more.

Please help me.


Accepted Solution

All Replies

  • PeterUK
    PeterUK Posts: 3,388  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    Most odd is the gateway for LAN1 192.168.20.1 subnet 255.255.255.0?

    Is their anything more in the logs that might help without the filter?

    Have you made a routing rule from LAN1 to next hop WAN1 by SNAT?

  • imaohw
    imaohw Posts: 124  Ally Member
    First Comment First Answer Friend Collector Sixth Anniversary

    Are you sure the server is on Lan1?

  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,511  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments

    Hi @vfm_IT

    Can you post the following CLI result for checking.

    Router> show zone user-define

    Router> show zone system-default

  • vfm_IT
    vfm_IT Posts: 13  Freshman Member
    First Comment Friend Collector Fourth Anniversary

    @PeterUK

    Your comment was a great help for me.

    But I can not figure out why the zyxel consider my server 192.168.20.2 is member of LAN2 (see attachment)


    While my LAN1 is 192.168.20.X/255.255.255.0 and my LAN2 is 191.168.X.X/255.255.0.0 (see attachment as a proof)


    I have to create a specific policy rule to make the zyxel allow outgoing access for my server 192.168.20.2 (see attachment as a proof)


    Can someone explain why? is this a bug on the zyxel router?

  • vfm_IT
    vfm_IT Posts: 13  Freshman Member
    First Comment Friend Collector Fourth Anniversary

    @Zyxel_Cooldia

    Hello

    Please find print screen attached


  • PeterUK
    PeterUK Posts: 3,388  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    What port is the server connected too on the USG110?

    How has port role setup?

  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,511  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments

    Hi @vfm_IT

    It seems host 192.168.20.2 goes to wrong interface.

    Can you get the CLI “show arp-table” to check where the host 192.168.20.2 come from? 


    Show arp table


  • vfm_IT
    vfm_IT Posts: 13  Freshman Member
    First Comment Friend Collector Fourth Anniversary

    @PeterUK

    Thanks for your help.

    I have been able to identify the issue and fix it.

    My server was connected on LAN2 and that´s why the USG was blocking outgoing traffic from my server.

Security Highlight