Zyxel ZyWALL USG 50 [28/185] Configuration steps

Zyxel ZyWALL USG 50 [28/185] Configuration steps
ZyWALL USG Support Notes
28
All contents copyright (c) 2010 ZyXEL Communications Corporation.
Please not that for the web server forwarding firewall rule, the service is http TCP port
80 instead of TCP 8080. Because in general packet flow, DNAT process precedes
firewall checking.
1.4. Setting up One to One NAT
1.4.1. Network Scenario
One to One NAT makes sure one local IP maps to one unique global IP, no matter the
traffic is outgoing from local to internet, or incoming from internet to local.
In the scenario above, we map the WAN global IP 200.0.0.1 to the intranet web server
192.168. 1.5. So, when an http client on the internet wants to access the server, its
original IP is 200.0.0.1. After the USG receives the traffic, it maps the destination
address to 192.168.1.5. When the server replies, its original source IP is 192.168.1.5,
when USG receives it, it will translate the source to 200.0.0.1 and send out to the
internet client.
After the One to One NAT rule is set, the USG will automatically generate a One to
One routing rule in the system, as discussed in section 1.1.2 Routing priority. So
when the server 192.168.1.5 initiates traffic to access internet, if there‟s no applicable
policy route, the USG will use this One to One routing, send out the traffic through
the WAN interface 200.0.0.1, and maps the source address to 200.0.0.1.
1.4.2. Configuration Steps
Step1. Go to Configuration > Network > NAT, click Add button to add one NAT rule.

Содержание

Похожие устройства

Скачать