What's new

Port Forwarding to device behind Zywall USG 50

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Aielman

New Around Here
Greetings everyone. I have an issue that probably plagues a few others out there with port forwarding problems.

My setup is as follows:

Comcast Cable modem -> Zywall USG50 -> Gig switch.

The switch serves four pcs and an xbox360 wired, and a Dlink wireless AP, which in turn serves an xbox360, PS3, 4 laptops and various handheld wireless devices.

Now I just got the USG50 to replace an aging Checkpoint VPN1-edge because I wanted to consolidate content filtering and AV on a network device to serve the devices that I can't put software on that my kids use. I also like having a hardware firewall because it gets it off the computers.

Now the problem I have is that I have 4 machines using both WoW and Steam, as well as 2 that use other BitTorrent aps, and two xbox360s. So...I need to set up port forwarding.

The hitch is, I can only set up a NAT to a single device on the firewall as it doesn't support UPnP.

So the question I have is this...is there another solution where I could perhaps buy a router with simple port forwarding and then set up the NAT on the USG50 to forward to that device, which could then route to all the clients that need to use that ap? I would then insert the router between the USG50 and the switch and set it up with a static address on the USG50 and use it as the dhcp server for the clients rather than the USG50.

Or...as another possibility, place a router inline between the cable modem and the USG 50, and then assign multiple IP addresses from the router to the USG 50, and then map those to each device?

Would something like that work and if so, any suggestions for hardware? If not, any other suggestions besides wait for a firmware update and hope they implement UPnP? heh.

Thanks in advance for any replies.
 
Last edited:
Some routers support triggered port forwarding. You can input an outbound port # to monitor, which will dynamically switch the inbound mapping.

But if you're going to try to use this for gaming, latency will probably be very bad due to the port forwarding switching times.

I assume you're referring to UPnP NAT Traversal, which automatically opens ports in a router's NAT firewall (if the router supports UPnP). While this is automatic (if the application supports it), again, it's not designed for what you're trying to do.

I would think that yours is a common situation and that the WoW/Steam either have some sort of server solution or support multiple ports.
 
Some routers support triggered port forwarding. You can input an outbound port # to monitor, which will dynamically switch the inbound mapping.

But if you're going to try to use this for gaming, latency will probably be very bad due to the port forwarding switching times.

I assume you're referring to UPnP NAT Traversal, which automatically opens ports in a router's NAT firewall (if the router supports UPnP). While this is automatic (if the application supports it), again, it's not designed for what you're trying to do.

I would think that yours is a common situation and that the WoW/Steam either have some sort of server solution or support multiple ports.

That's what I was referring to. I'm not really worried about gameplay as neither game requires port forward to play, but they do need it for downloads, WoW especially in order for the bittorrent client to work.

The xbox360s could be a problem too, but I don't think so. They will actually connect to Live without anything set up on the USG, but you end up with a warning that full NAT isn't implemented, which could cause problems with some services.

For the time being, I've just mapped the one for the time being, but it's going to be a problem for the other Xbox360.
 
I've played quite a few steam games, I've never had to do any port fowarding to get that working. My kid uses torrents now 'n then and I've never had to open/forward ports for that, nor would I ever.

One thing unfortunately that you'll find is as you get into business grade routers such as UTMs, you won't see home grade features like UPnP supported. Most businesses don't want the things running on their network that UPnP allows.

XBox live/360 stuff
• UDP 88
• UDP 3074
• TCP 3074
MTU on the router to be set to 1384.

Just a note..UTM appliances are good as an added layer of protection, as a compliment to a locally installed AV product. If your kid is into torrents/p2p stuff..that puts his computer at a very very high risk due to poisoned content. torrent/p2p traffic is broken down into chunks as it trickles in, utm appliances won't scan it as a whole file, thus trojans and malware that are "injected" into those downloads....slip right through UTMs.
 
I've got it set up for one of the xboxes, and the other works with "moderate nat" which gives it most of the functionality, but not all, according to MS.

I don't let the kids use bittorrent other than the one that's part of the Blizzard downloader. I'm the only one that uses it, (sparingly at that) and I will be keeping Kaspersky on my desktop as I have issues with using usb keys that have been in places I don't trust. But then again, I have a monster machine that can tolerate it better than the others on the network.

The downloader working on 4 computers and the additional xbox are my primary concerns with nat at this point. The checkpoint solution handled the xboxes with no problem, but never did handle the blizzard downloader.

Thanks for the suggestions. I guess we'll just plug away until we find a better solution.
 
Last edited:
Similar threads

Similar threads

Latest threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top