ZyXEL ZYWALL USG 100 User Guide - Page 105

What Can Go Wrong?, Configuration > Network > NAT - configure virtual server

Page 105 highlights

Chapter 5 Managing Traffic 2 Click Add in the Configuration table. The following screen appears. Select Enable, enter *.example.com as the Query Domain Name. Enter 300 in the Time to Live field to have DNS query senders keep the resolved DNS entries on their computers for 5 minutes. Select any in the IP Address field and WAN in the Zone field to apply this rule for all DNS query messages the WAN zone receives. Select Least Load - Total as the load balancing algorithm. Click Add to add WAN1 and WAN2 as the member interfaces. Click OK. Continue to go to the Configuration > Firewall and Configuration > Network > NAT screens to configure the corresponding firewall rules and NAT virtual server for the inbound service access. 5.4.1 What Can Go Wrong? • Using a greater TTL value makes DNS inbound load balancing become ineffective, although it can reduce the ZyWALL's loading as the DNS request senders does not need to send new queries to the ZyWALL that often. • If you choose Custom in the Load Balancing Member screen and enter another IP address for a member interface, make sure the entered IP address is configured in the corresponding firewall and NAT virtual server rules. ZyWALL USG100-PLUS User's Guide 105

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140

Chapter 5 Managing Traffic
ZyWALL USG100-PLUS User’s Guide
105
2
Click
Add
in the
Configuration
table. The following screen appears.
Select
Enable
, enter
*.example.com
as the
Query Domain Name
.
Enter
300
in the
Time to Live
field to have DNS query senders keep the resolved DNS entries on
their computers for 5 minutes.
Select
any
in the
IP Address
field and
WAN
in the
Zone
field to apply this rule for all DNS query
messages the WAN zone receives.
Select
Least Load - Total
as the load balancing algorithm.
Click
Add
to add WAN1 and WAN2 as the member interfaces. Click
OK
.
Continue to go to the
Configuration > Firewall
and
Configuration > Network > NAT
screens
to configure the corresponding firewall rules and NAT virtual server for the inbound service access.
5.4.1
What Can Go Wrong?
Using a greater TTL value makes DNS inbound load balancing become ineffective, although it can
reduce the ZyWALL’s loading as the DNS request senders does not need to send new queries to
the ZyWALL that often.
If you choose
Custom
in the
Load Balancing Member
screen and enter another IP address for
a member interface, make sure the entered IP address is configured in the corresponding firewall
and NAT virtual server rules.