Nat 1:1

DiGiSoft
DiGiSoft Posts: 6
First Comment
edited April 2021 in Security

Hi Sir,

I'm using USG40 with 2 VDSL PPOE, wan1 e wan2.

I have create 2 rule NAT 1:1

wan1_ppp -> IP_VDSL1 -> local IP 192.168.1.10 (local server) -> External port 5060 -> Internal port 5060

wan2_ppp -> IP_VDSL2 -> local IP 192.168.1.10 (local server) -> External port 5060 -> Internal port 5060

When I receive cuncurrently packet on wan1 and wan2, local server see external Source port is change.

Can I fix source port for 2 wan to one internal server?


Regards

Alex

All Replies

  • PeterUK
    PeterUK Posts: 2,656  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    edited August 2019

    The USG40 only has one WAN port and a OPT port are you sure you don't have the USG60?

    What firmware are you on?

  • Yes,

    I have config OPT as wan2

    Firmware version is: V4.33(AALA.0)


    Regards

  • PeterUK
    PeterUK Posts: 2,656  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer

    So you have traffic like this:

    > IP12.12.12.12 Source port 5060 – WAN1 IP123.123.123.123 local port 5060

    1:1NAT

    > IP12.12.12.12 Source port 5060 -IP192.168.1.10:5060

    --------------------------------------------------------------------------------------------------------------------------

    > IP12.12.12.12 Source port 5060 – OPT IP45.45.45.45 local port 5060

    1:1NAT

    > IP12.12.12.12 Source port changed -IP192.168.1.10:5060

    Because its to the same server and from the same source port NAT changes the source port I don't think theirs any way round this are you having VoIP issues because of this?

  • DiGiSoft
    DiGiSoft Posts: 6
    First Comment
    edited August 2019

    Hi PeterUK,

    it is strange,

    I can't have 2 different external IPs with the same port on 2 wan inbound with nat 1: 1 on the same server without the external port source changing?

    Trunk VoiP need trust IP and PORT external, Zywall change external source port dynamically.

    Alex

  • DiGiSoft
    DiGiSoft Posts: 6
    First Comment
    edited August 2019

    Can I change external port statically method?



    Alex

  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,431  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer

    Hi @DiGiSoft ,

    Welcome to Zyxel Community. ?

    You can enable SIP ALG and try it again.

    BTW, may I know what is your current VoIP phone issue? SIP Phone client cannot register to go on-line? 

    Phone can go on-line, but cannot make phone call? or can make phone call, but no voice?

     

    Enable SIP ALG at “CONFIGURATION > Network > ALG”


  • Hi Zyxel_Cooldia,

    no work with sip ALG,

    ALG replace public ip in sip message, server no accept this.

    My sip server needs to know port and ip source to accept sip messages, I configured trunk in my server (Ip and Port) and only this trunk is enable to accept message.

    Trunk use Ip authentication no User authentication


    Alex

  • No solution found,

    I think my Server plattform no compliant with Zywall.

    I must return my old firewall


    Alex

  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,431  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer

    Hi @DiGiSoft ,

    Can you do the test again and capture packets on USG-40 Wan and Lan interface?

    I would like to see the packet trace.

Security Highlight