Virtual Servers

See the Virtual Server (Port Forwarding) section for related information on these screens.

Virtual Server Overview

Virtual server is also known as port forwarding or port translation.

Virtual servers are computers on a private network behind the ZyWALL that you want to make available outside the private network. If the ZyWALL has only one public IP address, you can make the computers in the private network available by using ports to forward packets to the appropriate private IP address.

In the ZyWALL, you set up a virtual server for each forwarding rule. The first part of the virtual server defines the conditions required to forward the packet.

The second part of the virtual server controls where the packet is forwarded if the conditions are satisfied.

The original port range and the mapped port range must be the same size.

The ZyWALL checks virtual servers before it applies to-ZyWALL firewall rules, so to-ZyWALL firewall rules do not apply to traffic that is forwarded by virtual servers. The ZyWALL still checks regular (through-ZyWALL) firewall rules according to the source IP address and mapped IP address.

Virtual Server Summary Screen

The Virtual Server summary screen provides a summary of all virtual servers and their configuration. In addition, this screen allows you to create new virtual servers and edit and delete existing virtual servers.

Network > Virtual Server 

Label
Description
Total Virtual Servers
This is how many virtual server entries are configured in the ZyWALL.
entries per page
Select how many virtual server entries to display per page in the screen.
Page x of x
This is the number of the page of entries currently displayed and the total number of pages of entries. Type a page number to go to or use the arrows to navigate the pages of entries.
#
This field is a sequential value, and it is not associated with a specific virtual server.
Name
This field displays the name of the virtual server.
Interface
This field displays the interface on which packets for the virtual server were received.
Original IP
This field displays the original destination IP address (or address object) of packets for the virtual server. It displays any if there is no restriction on the original destination IP address.
Mapped IP
This field displays the new destination IP address for the packet.
Protocol
This field displays the service used by the packets for this virtual server. It displays any if there is no restriction on the services.
Original Port
This field displays the original destination port(s) of packets for the virtual server. This field is blank if there is no restriction on the original destination port.
Mapped Port
This field displays the new destination port(s) for the packet. This field is blank if there is no restriction on the original destination port.
Add icon
This column provides icons to add, edit, and remove virtual servers. In addition, you can activate and deactivate virtual servers.
To add a virtual server, click the Add icon at the top of the column. The Virtual Server Add/Edit screen appears.
To activate / deactivate a virtual server, click the Active icon next to the virtual server.
To edit a virtual server, click the Edit icon next to the virtual server. The Virtual Server Add/Edit screen appears.
To delete a virtual server, click on the Remove icon next to the virtual server. The web configurator confirms that you want to delete it before doing so.

Virtual Server Add/Edit

The Virtual Server Add/Edit screen lets you create new virtual servers and edit existing ones.

Network > Virtual Server > Edit 

Label
Description
Enable
Use this option to turn the virtual server on or off.
Name
Type in the name of the virtual server. The name is used to refer to the virtual server. You may use 1-31 alphanumeric characters, underscores(_), or dashes (-), but the first character cannot be a number. This value is case-sensitive.
Interface
Select the interface on which packets for the virtual server must be received.
Original IP
Use the drop-down list box to indicate which destination IP address this virtual server supports. Choices are:
Any - this virtual server supports the IP address of the selected interface.
User Defined - this virtual server supports a specific IP address, specified in the User Defined field.
HOST address - the drop-down box lists all the HOST address objects in the ZyWALL. If you select one of them, this virtual server supports the IP address specified by the address object.
Select Create Object to configure a new IP address object.
User Defined
This field is available if Original IP is User Defined. Type the destination IP address that this virtual server supports.
Mapped IP
Type the translated destination IP address, if this virtual server forwards the packet.
Mapping Type
Use the drop-down list box to select how many original destination ports this virtual server supports for the selected destination IP address (Original IP). Choices are:
Any - this virtual server supports all the destination ports.
Port - this virtual server supports one destination port.
Ports - this virtual server supports a range of destination ports.
Protocol Type
This field is available if Mapping Type is Port or Ports. Select the protocol supported by this virtual server. Choices are TCP, UDP, or Any.
Original Port
This field is available if Mapping Type is Port. Enter the original destination port this virtual server supports.
Mapped Port
This field is available if Mapping Type is Port. Enter the translated destination port if this virtual server forwards the packet.
Original Start Port
This field is available if Mapping Type is Ports. Enter the beginning of the range of original destination ports this virtual server supports.
Original End Port
This field is available if Mapping Type is Ports. Enter the end of the range of original destination ports this virtual server supports.
Mapped Start Port
This field is available if Mapping Type is Ports. Enter the beginning of the range of translated destination ports if this virtual server forwards the packet.
Mapped End Port
This field is available if Mapping Type is Ports. Enter the end of the range of translated destination ports if this virtual server forwards the packet.
OK
Click OK to save your changes back to the ZyWALL.
Cancel
Click Cancel to return to the Virtual Server summary screen without creating the virtual server (if it is new) or saving any changes (if it already exists).