Port Trigger Screen - ZyXEL Communications ARMOR G5 User Manual

Hide thumbs Also See for ARMOR G5:
Table of Contents

Advertisement

Table 27 Settings > Internet > Passthrough (continued)
L ABEL
IPSEC
Apply
Cancel
9.7 Po rt T rig g e r Sc re e n
Some services use a dedicated range of ports on the client side and a dedicated range of ports on the
server side. With regular port forwarding, you set a forwarding port in NAT to forward a service (coming
in from the server on the WAN) to the IP address of a computer on the client side (LAN). The problem is
that port forwarding only forwards a service to a single LAN IP address. In order to use the same service
on a different LAN computer, you have to manually replace the LAN computer's IP address in the
forwarding port with another LAN computer's IP address.
Trigger port forwarding addresses this problem. Trigger port forwarding allows computers on the LAN to
dynamically take turns using the service. The Zyxel Device records the IP address of a LAN computer that
sends traffic to the WAN to request a service with a specific port number and protocol (a "trigger" port).
When the Zyxel Device's WAN port receives a response with a specific port number and protocol
("open" port), the Zyxel Device forwards the traffic to the LAN IP address of the computer that sent the
request. After that computer's connection for that service closes, another computer on the LAN can use
the service in the same manner. This way you do not need to configure a new IP address each time you
want a different LAN computer to use the application.
Note: TCP port 7547 is reserved for system use.
Note: The maximum number of trigger ports for a single rule or all rules is 999.
Note: The maximum number of open ports for a single rule or all rules is 999.
Trigger Port Forwarding Process: Example
Fig ure 49
Chapter 9 WAN
DESC RIPT IO N
Select
to allow VPN clients to make outbound IPSec connections. It is required in
Ena b le
order to connect to a IPSec VPN account. If
request to a VPN server, the server will reply to the NBG7815 and the NBG7815 will drop the
request. When
is enabled, the NBG7815 will forward the reply from the VPN server to
IPSEC
the client that initiated the request, and the connection will establish successfully.
Click
to save your changes back to the NBG7815.
Apply
Click
to begin configuring this screen afresh.
C a nc e l
NBG7815 User's Guide
94
is disabled, then when a client sends a
IPSEC

Advertisement

Table of Contents
loading

This manual is also suitable for:

Nbg7815

Table of Contents