Answer the question
In order to leave comments, you need to log in
[SOLVED] ZyXEL ZyWALL2 plus hardware firewall + port forwarding = failure
Good afternoon, hackers!
There is Internet on RJ-45 with white IP х.х.х.х
There is a ZyXEL ZyWALL2 plus router
There is a computer on the network with the address 192.168.100.15
The RDP server on port 3389 is running on the computer
The task is trivial: to make terminal access to the computer available from the Internet. Let's set aside the security issues of such a solution for the time being.
According to the manual, the configuration was carried out in 2 stages:
1. Set up a rule in port forwarding
2. Set up a rule in firewall
Next, we check, but there is no effect
I look at the log, but everything is fine
Connection before and after Zyxel works successfully:
1. Access from the Internet to the Web Zyxel ZyWALL2 plus interface has
2. Zyxel ZyWALL2 plus has access to the computer from 192.168.100.15
Checked by pinging from ZyWALL2, working in its console via ssh
3. Port 3389 on 192.168.100.15 is open, checked from another computer on the network
Please help those who have encountered a similar problem.
Thanks in advance.
PS The problem was solved after 3 gestures
1. The firmware was updated to the latest version
2. The rules in the firewall were rewritten
3. On a computer in the network with the address 192.168.100.15 (which runs the RDP server on port 3389), the gateway and DNS was registered ZyWALL.
PPS
The firewall rules appear to work like this:
1. First, port xxxx (for example) opens in the chain W to W/zyxel
2. Port forwarding is configured from xxxx to 3389 of the computer 192.168.100.15
3. Finally, port 3389 is opened in the W to L chain
Answer the question
In order to leave comments, you need to log in
Good afternoon!
I have not worked with this equipment, but I think that I understand how it works :) In general, I suspect that you described the rule a little incorrectly, the fact is that you wrote a rule that allows packets to pass through the WAN-to-LAN chain, traffic that enters this chain does not contain dst ip 192.168… (your computer), since this rule is probably applied to traffic even before NAT translation. Add an additional WAN-to-WAN rule with src ip any and dst-ip xxxx (your white IP address).
Zuksel has a technical support service, leave a request there - they answer you.
Also, if the matter is urgent, you can dial the handset and call.
in the WAN to LAN chain, you need to add a rule!
Source Address: any
Destination Address: 192.168.100.15
Service Type: RDP
Action: permit
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question