Tutorial - How To Allow Public Access To A Server - ZyXEL Communications UAG Series Cli Reference Manual

Unified access gateway
Hide thumbs Also See for UAG Series:
Table of Contents

Advertisement

Chapter 12 Virtual Servers

12.2.2 Tutorial - How to Allow Public Access to a Server

This is an example of making an HTTP (web) server in the DMZ zone accessible from the Internet
(the WAN zone). You will use a public IP address of 1.1.1.2 on the wan1 interface and map it to the
HTTP server's private IP address of 192.168.3.7.
Figure 17 Public Server Example Network Topology
192.168.3.7
Follow the following steps for the setting.
Configure Address object
1
Create two address objects. One is named DMZ_HTTP for the HTTP server's private IP address of
192.168.3.7. The other one is named wan1_HTTP for the wan1 public IP address of 1.1.1.2.
Router# configure terminal
Router(config)# address-object DMZ_HTTP 192.168.3.7
Router(config)# address-object wan1_HTTP 1.1.1.2
Router(config)#
Configure NAT
2
You need a NAT rule to send HTTP traffic coming to IP address 1.1.1.2 on wan1 to the HTTP server's
private IP address of 192.168.3.7. Use the following settings:
• This NAT rule is for any HTTP traffic coming in on wan1 to IP address 1.1.1.2.
• The NAT rule sends this traffic to the HTTP server's private IP address of 192.168.3.7 (defined
in the DMZ_HTTP object).
• HTTP traffic and the HTTP server in this example both use TCP port 80. So you set the port
mapping type to "port", the protocol type to "TCP", and the original and mapped ports to "80".
Router(config)# ip virtual-server To-VirtualServer-WWW interface wan1 original-ip
wan1_HTTP map-to DMZ_HTTP map-type port protocol tcp original-port 80 mapped-port 80
Router(config)#
Configure firewall
3
Create a firewall rule to allow HTTP traffic from the WAN zone to the DMZ web server.
Router(config)# firewall insert 1
Router(firewall)# description To-VirtualServer-WWW
Router(firewall)# from WAN
Router(firewall)# to DMZ
Router(firewall)# destinationip DMZ_HTTP
Router(firewall)# service HTTP
Router(firewall)# exit
Router(config)# write
Router(config)#
Now the public can go to IP address 1.1.1.2 to access the HTTP server.
104
DMZ
WAN
1.1.1.2
UAG CLI Reference Guide

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents