ZyXEL ZYWALL USG 100 User Guide - Page 106

How to Allow Public Access to a Web Server, 5.5.1 Con NAT, Con NAT

Page 106 highlights

Chapter 5 Managing Traffic 5.5 How to Allow Public Access to a Web Server This is an example of making an HTTP (web) server in the DMZ zone accessible from the Internet (the WAN zone). In this example you have public IP address 1.1.1.1 that you will use on the WAN interface and map to the HTTP server's private IP address of 192.168.3.7. Figure 41 Public Server Example Network Topology 192.168.3.7 DMZ 1.1.1.1 5.5.1 Configure NAT Create a NAT rule to send HTTP traffic coming to WAN IP address 1.1.1.1 to the HTTP server's private IP address of 192.168.3.7. 1 Click Configuration > Network > NAT > Add > Create New Object > Address and create an IPv4 host address object named DMZ_HTTP for the HTTP server's private IP address of 192.168.3.7. Repeat to create a host address object named Public_HTTP_Server_IP for the public WAN IP address 1.1.1.1. 2 Configure the NAT rule. For the Incoming Interface select the WAN interface. Set the Original IP to the Public_HTTP_Server_IP object and the Mapped IP to the DMZ_HTTP object. HTTP traffic and the HTTP server in this example both use TCP port 80. So you set the Port Mapping Type to Port, the Protocol Type to TCP, and the original and mapped ports to 80. Keep Enable NAT Loopback selected to allow users connected to other interfaces to access the HTTP server. 106 ZyWALL USG100-PLUS User's Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140

Chapter 5 Managing Traffic
ZyWALL USG100-PLUS User’s Guide
106
5.5
How to Allow Public Access to a Web Server
This is an example of making an HTTP (web) server in the DMZ zone accessible from the Internet
(the WAN zone). In this example you have public IP address 1.1.1.1 that you will use on the WAN
interface and map to the HTTP server’s private IP address of 192.168.3.7.
Figure 41
Public Server Example Network Topology
5.5.1
Configure NAT
Create a NAT rule to send HTTP traffic coming to WAN IP address 1.1.1.1 to the HTTP server’s
private IP address of 192.168.3.7.
1
Click
Configuration > Network > NAT >
Add > Create New Object > Address
and create an
IPv4 host address object named DMZ_HTTP for the HTTP server’s private IP address of
192.168.3.7. Repeat to create a host address object named Public_HTTP_Server_IP for the public
WAN IP address 1.1.1.1.
2
Configure the NAT rule.
For the
Incoming Interface
select the WAN interface.
Set the
Original IP
to the
Public_HTTP_Server_IP
object and the
Mapped IP
to the
DMZ_HTTP
object.
HTTP traffic and the HTTP server in this example both use TCP port 80. So you set the
Port
Mapping Type
to
Port
, the
Protocol Type
to
TCP
, and the original and mapped ports to 80.
Keep
Enable NAT Loopback
selected to allow users connected to other interfaces to access the
HTTP server.
DMZ
192.168.3.7
1.1.1.1