Hello all:
I am currently considering UT to replace my current Zyxel Zywall USG 100 UTM Firewall due to several extreme performance issues being experienced with the device. Before I purchase hardware and such, I would like to make sure that UT can do what I am wanting to do. My current logical setup is as follows:
Modem --> Zywall (Unit has 6 Interfaces)
Zywall P1 --> Modem (64 Public IP Addresses)
Zywall P2 --> Not Used (unit supports WAN Load Balancing)
Zywall P3 --> Internal LAN (10.0.1.1/24)
Zywall P4 --> DMZ LAN (10.0.2.1/24)
Zywall P5 --> Guest LAN (10.0.3.1/24)
Zywall P6 --> Dev LAN (10.0.4.1/24)
Each port is connected to smart switches and are on separate VLANs (No tagging is done at the Zywall or on the Zywall ports)
Essentially, traffic from the Internal LAN can go, mostly unrestricted, to any of the other LANs or to the Internet (a few ports are blocked to prevent spamming and such). Traffic on the DMZ LAN can go to the internet (mostly unrestricted). However, firewall rules are in place to only allow for certain communication from the DMZ LAN to other LANs (for example, DNS is allowed to internal DNS servers via specific IPs and ports, etc). Guest traffic is mostly unrestricted to the internet with the Zywall Captive Portal turned off (it doesn't work very well). The guest LAN cannot communicate with any other LAN on the network. Lastly, the Dev LAN can communicate with the internet mostly unrestricted and can also communicate with certain devices on the DMZ LAN. No other communication is permitted from that network (it's basically treated as a second untrusted DMZ that holds dev labs and dev machines).
There are a few SNATs (1:1 NATs) with port forwarding from IP addresses (I believe in UT, they would be aliases) that point to machines in the DMZ. There is one alias that SNATs to a machine that lives in the Internal LAN (single port forward).
So, my questions are this.
- Can I do this with UT (community/lite edition)?
- If not in the lite/community edition, what about the paid verions?
Thanks for your time.