Solved

Zywall USG 100 Firewall

Posted on 2015-02-04
5
184 Views
Last Modified: 2015-02-10
Hello,
I am now setting up one Zywall USG 100 (latest firware applied), and I want to forward port 21 to internal server. I follow the steps from the manual, but it is not working. If I disable the firewall, it is working.

I am attaching the manual/tutorial. I used the steps from page 167 to 170. I cannot copy it here as it document is secured.
ZYWALL-USG-200-2.20.pdf
0
Comment
Question by:goliveuk
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 40

Expert Comment

by:noci
ID: 40591737
Hi port 21 is FTP (i expect that you want to use it as such..)
That not only means that port 21 needs to be forward but also the accompaning ports.
for file transfer. Did you enable the FTP ALG?

So besides a NAT rule
+ Firewall rule to pass on port 21
you also need to enable the ALG/FTP

Instead of using FTP please consider the use of SSH/SCP/SFTP...
that doesn't expose a users password like FTP does. It also makes the FTP transfer more private w.r.t. content. (and at least easier on network resources.).
0
 

Author Comment

by:goliveuk
ID: 40593439
Hello noci,


ALG/FTP is enabled.
0
 
LVL 40

Expert Comment

by:noci
ID: 40595571
Ok, can you make a screen shot of the config & post here. public IP addresses can be blurred if needed.
0
 

Author Comment

by:goliveuk
ID: 40598218
Hello,

Here are some screens from the Zywall
Addresses.png
ALG.png
Firewall.png
nat.png
0
 
LVL 40

Accepted Solution

by:
noci earned 500 total points
ID: 40599877
Ah, firewall: WAN-> DMZ, where your FTP server has an address on the LAN1 port
so firewall should be WAN->LAN1 or you need to move the FTP server to the DMZ port.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

There are two basic ways to configure a static route for Cisco IOS devices. I've written this article to highlight a case study comparing the configuration of a static route using the next-hop IP and the configuration of a static route using an outg…
This is the first one of a series of articles I’ll be writing to address technical issues that are always referred to as network problems. The network boundaries have changed, therefore having an understanding of how each piece in the network  puzzl…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

695 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question