-
How to configure remote access to a PC via Nebula?
Question: I am trying to configure remote access to a PC via Nebula. How to configure on Nebula firewall? Answer: You can follow the guides in these FAQs to configure a NAT rule with RDP port 3389 on Nebula firewall. [ATP/FLEX] How to configure a NAT Rule (Virtual Server) on Nebula? [ATP/FLEX] How to configure a NAT rule…
-
How to remove the NAT rule using CLI for USG Flex H series models?
Scenario : In this article How to check the NAT rule using CLI for USG Flex H series models? Users can use CLI to check the current NAT rules. Users may want to know how to remove the NAT rule using CLI. Answer : Please enter the CLI command "show config vrf main virtual-server rule" to check the current NAT rules on the…
-
How to check the NAT rule using CLI for USG Flex H series models?
Scenario : Users usually create NAT rules via the Web-GUI (as shown below). While troubleshooting NAT-related issues, users may use the CLI mode. This guide will show you how to check the NAT rules in CLI mode. Answer : Please enter the CLI command "show config vrf main virtual-server rule" to check the current NAT rules…
-
[Nebula]Is it possible to configure inbound/outbound NAT in Nebula VPN?
Question Is it possible to configure inbound/outbound NAT in Nebula VPN? Answer At the current design stage, Nebula does not support inbound/outbound NAT. However, it can be configured in on-premise mode.
-
[Nebula]Is it possible to export NAT rules from Nebula?
Question Is it possible to export NAT rules from Nebula? Answer It is not possible to export NAT rules from Nebula. However, we can obtain the NAT configuration by accessing the device via SSH and using the CLI command "debug sdwan show firewall running-config". Assume the NAT rule is configured in Nebula. We can see the…
-
How do I set up NAT port forwarding for remote AP usage on the firewall?
Scenario : Users may wish to use the remote AP service behind a NAT scenario. For example, in the topology below, the remote AP will establish a VPN service to the destination firewall USG Flex 100. Remote AP === internet === USG Flex 200 === (NAT ports forwarding) === USG Flex 100 Users may wonder how to set up NAT port…
-
[Nebula] I cannot access my internal server. What steps should I take to check for NAT issues?
Question: On Nebula, I have configured my NAT ports correctly, but I am unable to access my server using the public IP. What steps should I take to ensure visibility of my server with the public IP? Answer: If you've configured NAT ports correctly but still cannot access your server using the public IP, here are some steps…
-
[ATP/FLEX] How to configure a NAT rule on nebula if the firewall is behind NAT?
Scenario: In a situation where the firewall is in a NAT environment and receives a private IP from the above router or gateway, how should a NAT rule be configured in the Nebula firewall? This article will explain how to configure a NAT rule on nebula if the firewall is behind another NAT router or firewall. Answer: In…
-
Why is the Virtual Server or 1:1 NAT configuration correct, but the NAT still cannot work?
Background and Scenario: We have noticed that some users encounter a situation where the Virtual Server or 1:1 NAT configuration is correct, but the NAT still does not work. What could be the possible reason for this issue? Answer: The possible reason is usually related to the security policy allowing the traffic from WAN…
-
How to set a range of IP addresses on ATP/USG FLEX interface?
Question: The ISP provided me a range of public IP addresses (10 public IP addresses). I would like to set these IP addresses on ATP/USG FLEX but ATP/USG FLEX only supports up to 4 virtual interfaces. How can I set 10 public IP addresses on ATP/USG FLEX in order to publish 10 servers to the Internet? Answer: You can use…
-
[ATP/FLEX] How to configure a NAT Rule (Virtual Server) on Nebula?
The Virtual
Server feature is able to publish internal servers to the internet which allows
you to access services in the internal network behind Firewall. This article will explain step-by-step how to configure a NAT rule (Virtual Server), also known as Port Forwarding, on your Nebula firewalls. By following these steps…
-
What is the difference between Virtual Server and 1:1 NAT?
Question I would like to use NAT feature to publish an internal server for external users. On the NAT Add/Edit page, there are Virtual Server and 1:1 NAT. Which one should I choose? What is the difference between Virtual Server and 1:1 NAT? Answer Both Virtual Server and 1:1 NAT are able to publish internal servers to…
-
Implement Inbound Server Load Balance
Inbound Server Load
Balance For load Balance or redundant purpose, some enterprises might have more than one ISP or Web Server to handle
incoming service requests. This article will explain how to achieve the goal on
Zyxel Firewall. Before Begin Firewall uses Algorithm to respond to a DNS query with the IP address…
-
How to set a range of IP addresses on USG interface?
Scenario: My ISP provided me a range of public IP addresses. (10 public IP addresses)I would like to set these IP addresses on USG, but USG only supports up to 4 virtual interfaces. How can I set that on USG? I would like to publish 10 servers to the Internet. Configuration: If ISP provided a range of IP addresses, you can…
-
What is the procedure to configure SBG3300 for WOL (Wake on LAN)?
Scenario: The User A wants
to use WOL (Wake on LAN)
feature to awake the Target
PC from Port:
8080 at SBG3300 WAN side. To meet this requirement, SBG3300 should add NAT rule &
Static ARP for the target
PC. What is the procedure to configure SBG3300
for this purpose? Step-by-Step: Step 1: Go
to Network Setting > NAT > Port…
-
How to setup port forwarding to my internal RDP PC?
You can add the virtual server rule for your requirement: (1) Original IP: The IP address your ISP provided. (2) Mapped IP: The IP address your Server IP. (3)Original port: The port number which you would like to connected from outside. (4)Mapped port: The port number which your server is servicing. And make sure your…
-
How to Allow Public Access to a Server Behind ZyWALL/USG?
SCENARIO DESCRIPTION: This is an example of using ZyWALL/USG to configure a securely access to internal server behind ZyWALL/USG with network address translation (NAT). The Internet users can reach this server directly by its public IP address and a NAT mapping rule will forward the traffic from the Internet to the…
-
How can the inbound destination NAT be used to hide the server’s real IP via a VPN tunnel?
A customer requires that the server’s real IP is hidden when using site-to-site VPN. This can be done by using an inbound destination NAT to hide the server’s real IP when VPN is established. The inbound DNAT works as a virtual server. It can redirect the VPN traffic to the internal server. Steps: VPN connections: Policy…
-
How to configure IPSec Site to Site VPN while one Site is behind a NAT router
SCENARIO DESCRIPTION: This example shows how to use the VPN Setup Wizard to create a IPSec Site to Site VPN tunnel between ZyWALL/USG devices. The example instructs how to configure the VPN tunnel between each site while one Site is behind a NAT router. When the IPSec Site to Site VPN tunnel is configured, each site can be…