Solved

Forwarding single port to seperate machine ZyWall USG 50

Posted on 2011-03-15
7
3,912 Views
Last Modified: 2012-05-11
We set up a ZyWALL USG 50 on our network. We have everything being forwarded to the server on the network. However there is one port that we would like to forward to a separate machine on the network. Set up 1:1 NAT for the server and set up a second 1:1 NAT for the separate machine, but it still forwards to the server.
0
Comment
Question by:mjkisic
  • 4
  • 3
7 Comments
 
LVL 33

Accepted Solution

by:
it_saige earned 250 total points
ID: 35141499
Move the nat rule for the second machine in front of the nat rule for the server.  If the ACLs in the ZyWall are configured properly, then the rule for the second machine will be resolved before the rule for the server is resolved.

-saige-
0
 

Author Comment

by:mjkisic
ID: 35141614
Alright so we have two NAT's.
the first one is 1:1 NAT to the PC.
Interface: WAN1
Original IP (Static IP)
Mapped IP (Internal IP)
Protocol TCP

Second is,
1:1 NAT to the server
Interface WAN1
Original IP (static IP)
Mapped IP (Server Internal IP)
Protocol Any
0
 
LVL 33

Expert Comment

by:it_saige
ID: 35141655
That should be all you need.

Can you post your ACL's (remember to remove any personal/confidential information).

-saige-
0
VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

 

Author Comment

by:mjkisic
ID: 35141673
What specifically?
0
 

Author Comment

by:mjkisic
ID: 35141716
Priority 1 from WAN to LAN any user any source
destination (Internal computer)
service (TCP Port)
allow

Priority 2 from WAN to LAN
and user
source (any)
destination (internal server)
service "sharepoint services)
allow
0
 
LVL 33

Expert Comment

by:it_saige
ID: 35141955
That should be good.

-saige-
0
 

Author Comment

by:mjkisic
ID: 35142107
It didn't kick in until just now for some reason, but that worked. Thank you.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Opening Ports 18 92
E-mail alerts from Cisco ASA Firepower 3 59
l2tp tunnel from pc to router 14 85
How to route a specific IP address to a specific port on a Fortinet 90D 2 32
The Need In an Active Directory enviroment, the PDC emulator provide time synchronization for the domain. This is important since Active Directory uses Kerberos for authentication.  By default, if the time difference between systems is off by more …
I'm a big fan of Windows' offline folder caching and have used it on my laptops for over a decade.  One thing I don't like about it, however, is how difficult Microsoft has made it for the cache to be moved out of the Windows folder.  Here's how to …
This tutorial gives a high-level tour of the interface of Marketo (a marketing automation tool to help businesses track and engage prospective customers and drive them to purchase). You will see the main areas including Marketing Activities, Design …
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…

776 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question