Zyxel ZyWALL USG 50 [34/185] Nat with proxy arp

Zyxel ZyWALL USG 2000 [34/185] Nat with proxy arp
ZyWALL USG Support Notes
34
All contents copyright (c) 2010 ZyXEL Communications Corporation.
After NAT Loopback is enabled, no policy route is needed, USG will automatically
checking routing table. And it will only do SNAT for the local clients in the same
subnet with the server. The source addresses of clients from WAN side and local
clients in the other subnets will remain the original.
1.7. NAT with Proxy ARP
Sometimes user may want to use some non-interface IP as the global IP for some
servers, or want to do SNAT for some local traffic to map the source address to some
non-interface IP.
For example, user has 3 public IP from ISP, 200.0.0.1, 200.0.0.2, 200.0.1.1. User set
200.0.0.1 as WAN 1 IP, 200.0.1.1 as WAN2 IP. But he/she wants users to use
200.0.0.2 to access the intranet server, e.g. 192.168.1.5, by adding one NAT rule as
below:
Incoming interface: WAN1
Original IP: 200.0.0.2
Mapped IP: 192.168.1.5
In ZLD v2.1x, after user added the NAT rule as above, it will automatically created
one Virtual Interface on the Incoming interface with the non-interface IP. In this
example, it will add one Virtual interface on WAN1, with IP address 200.0.0.2.
However, there‟s a disadvantage in this way: after the NAT rule is created, not only
the traffic to access the intranet server will be allowed, but the USG can also be
accessed by this non-interface IP, which brings a security concern that some hackers
may use this non-interface IP to login USG to malicious actions on the USG.
Besides, you cannot map the outgoing traffic‟s source IP to a non-interface IP.
Because the USG has no way to know that the non-interface IP belongs to itself.
In ZLD v2.20, after user added the NAT rule as above, it will automatically create
proxy ARP table to make the non-interface IP corresponding the incoming interface‟s
MAC. It will only allow the traffic accessing the intranet server in this NAT rule,
other traffic will be dropped by the USG.
Also, in ZLD v2.20, the USG can map outgoing traffic‟s source IP to a non-interface
IP by creating proxy ARP table to map the non-interface IP to the outgoing interface‟s
MAC.

Содержание

Похожие устройства

Скачать