Solved

Forwarding single port to seperate machine ZyWall USG 50

Posted on 2011-03-15
7
3,918 Views
Last Modified: 2012-05-11
We set up a ZyWALL USG 50 on our network. We have everything being forwarded to the server on the network. However there is one port that we would like to forward to a separate machine on the network. Set up 1:1 NAT for the server and set up a second 1:1 NAT for the separate machine, but it still forwards to the server.
0
Comment
Question by:mjkisic
  • 4
  • 3
7 Comments
 
LVL 33

Accepted Solution

by:
it_saige earned 250 total points
ID: 35141499
Move the nat rule for the second machine in front of the nat rule for the server.  If the ACLs in the ZyWall are configured properly, then the rule for the second machine will be resolved before the rule for the server is resolved.

-saige-
0
 

Author Comment

by:mjkisic
ID: 35141614
Alright so we have two NAT's.
the first one is 1:1 NAT to the PC.
Interface: WAN1
Original IP (Static IP)
Mapped IP (Internal IP)
Protocol TCP

Second is,
1:1 NAT to the server
Interface WAN1
Original IP (static IP)
Mapped IP (Server Internal IP)
Protocol Any
0
 
LVL 33

Expert Comment

by:it_saige
ID: 35141655
That should be all you need.

Can you post your ACL's (remember to remove any personal/confidential information).

-saige-
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 

Author Comment

by:mjkisic
ID: 35141673
What specifically?
0
 

Author Comment

by:mjkisic
ID: 35141716
Priority 1 from WAN to LAN any user any source
destination (Internal computer)
service (TCP Port)
allow

Priority 2 from WAN to LAN
and user
source (any)
destination (internal server)
service "sharepoint services)
allow
0
 
LVL 33

Expert Comment

by:it_saige
ID: 35141955
That should be good.

-saige-
0
 

Author Comment

by:mjkisic
ID: 35142107
It didn't kick in until just now for some reason, but that worked. Thank you.
0

Featured Post

Connect further...control easier

With the ATEN CE624, you can now enjoy a high-quality visual experience powered by HDBaseT technology and the convenience of a single Cat6 cable to transmit uncompressed video with zero latency and multi-streaming for dual-view applications where remote access is required.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A brief overview to explain gateways, default gateways and static routes OR NO - you CANNOT have two default gateways on the same server, PC or other Windows-based network device. In simple terms a gateway is formed when a computer such as a serv…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question