Chapter 13 NAT
ZyWALL USG Series User’s Guide
445
13.3 NAT Technical Reference
Here is more detailed information about NAT on the Zyxel Device.
NAT Loopback
Suppose an NAT 1:1 rule maps a public IP address to the private IP address of a LAN SMTP e-mail server
to give WAN users access. NAT loopback allows other users to also use the rule’s external IP to access
the mail server.
For example, a LAN user’s computer at IP address 192.168.1.89 queries a public DNS server to resolve the
SMTP server’s domain name (xxx.LAN-SMTP.com in this example) and gets the SMTP server’s internal
public IP address of 1.1.1.1.
Figure 307
LAN Computer Queries a Public DNS Server
Security Policy
By default the security policy blocks incoming connections from external addresses. After
you configure your NAT rule settings, click the
Security Policy
link to configure a security
policy to allow the NAT rule’s traffic to come in.
The Zyxel Device checks NAT rules before it applies To-Zyxel Device security policies, so To-
Zyxel Device security policies, do not apply to traffic that is forwarded by NAT rules. The
Zyxel Device still checks other security policies, according to the source IP address and
internal IP address.
OK
Click
OK
to save your changes back to the Zyxel Device.
Cancel
Click
Cancel
to return to the
NAT
summary screen without creating the NAT rule (if it is new)
or saving any changes (if it already exists).
Table 155 Configuration > Network > NAT > Add (continued)
LABEL
DESCRIPTION
192.168.1.21
xxx.LAN-SMTP.com =?
LAN
DNS
192.168.1.89
xxx.LAN-SMTP.com = 1.1.1.1
1.1.1.1
Summary of Contents for USG110
Page 27: ...27 PART I User s Guide ...
Page 195: ...195 PART II Technical Reference ...
Page 309: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 309 ...
Page 313: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 313 ...
Page 358: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 358 ...
Page 373: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 373 ...