99
• Add P5 (lan2) to the DMZ interface (Note: In USG 20/20W, use P4 (lan2) instead of P5 in this
example). The DMZ interface is used for a protected local network. It uses IP address
192.168.3.1 and serves as a DHCP server by default.
• You want to be able to apply specific security settings for the VPN tunnel created by the Quick
Setup - VPN Setup wizard (named WIZ_VPN). So you create a new zone and add WIZ_VPN to
it.
Figure 21 Ethernet Interface, Port Roles, and Zone Configuration Example
1.2.1 Configure a WAN Ethernet Interface
You need to assign the USG’s wan1 interface a static IP address of 1.2.3.4.
Click Configuration > Network > Interface > Ethernet and double-click the wan1 interface’s
entry in the Configuration section. Select Use Fixed IP Address and configure the IP address,
subnet mask, and default gateway settings and click OK.
1.2.2 Configure Port Roles
Here is how to take the P5 port from the lan2 interface and add it to the dmz interface.
1 Click Configuration > Network > Interface > Port Role.