Sonicwall TZ500 IP/端口转发及SSH连接转发配置咨询
Hey Tedison, great question! Yes, forwarding all SSH connections your SonicWall TZ500 receives to an external IP is absolutely doable. Let’s walk through the exact steps to set this up properly:
Step 1: Log into your SonicWall Management Interface
First, fire up your browser and navigate to your SonicWall’s management IP (usually 192.168.168.168 by default) and log in with your admin credentials.
Step 2: Create Address Objects for Both Targets
You’ll need two address objects to define the endpoints of this forwarding setup:
- One for your SonicWall’s public WAN IP (the IP that incoming SSH connections will hit)
- One for the external target IP you want to forward those connections to
To create these:
- Go to Network > Address Objects
- Click Add
- For the WAN IP object:
- Name it something like
SonicWall_WAN_IP - Set Zone Assignment to
WAN - Choose Type as
Hostand enter your public WAN IP address
- Name it something like
- For the external target IP object:
- Name it something like
External_SSH_Target - Set Zone Assignment to
WAN(since it’s an external IP) - Choose Type as
Hostand enter the target external IP
- Name it something like
- For the WAN IP object:
- Save both objects once configured
Step 3: Confirm or Create a Service Object for SSH
Most SonicWalls have a default SSH service object, but let’s verify or create one if needed:
- Go to Network > Services
- If you don’t see
SSHin the list, click Add- Name it
SSH - Set Protocol to
TCP - Enter
22for both Start Port and End Port
- Name it
- Save the service object
Step 4: Configure a NAT Policy for Port Forwarding
This is the core rule that tells the SonicWall to route incoming SSH traffic to your target IP:
- Go to Policy > NAT Rules
- Click Add to create a new rule
- Under Original Source, select
Any(or restrict to specific IPs if you only want certain senders to access this) - Under Original Destination, select the
SonicWall_WAN_IPaddress object you created - Under Original Service, select the
SSHservice object - Under Translated Source, select
Original - Under Translated Destination, select the
External_SSH_Targetaddress object - Under Translated Service, select
Original(we want to keep the SSH port 22 intact) - Set Inbound Interface to your WAN interface (usually
X1by default) - Set Outbound Interface to your WAN interface as well (since we’re forwarding to an external IP)
- Give the rule a descriptive name like
Forward_SSH_to_External_Target
- Under Original Source, select
- Save the NAT rule
Step 5: Adjust Firewall Rules to Allow Inbound Traffic
By default, SonicWalls block inbound traffic, so you’ll need to explicitly allow incoming SSH to your WAN IP:
- Go to Policy > Firewall Rules
- Click Add under the WAN to WAN section (since we’re routing traffic from WAN to another WAN-based IP)
- Set Source to
Any(or restricted IPs for tighter security) - Set Destination to
SonicWall_WAN_IP - Set Service to
SSH - Set Action to
Allow - Add a description like
Allow Inbound SSH for Forwarding
- Set Source to
- Save the firewall rule
Step 6: Test the Configuration
Now, test from a device outside your network: run ssh <your-sonicwall-wan-ip> and it should route directly to the external target IP you specified. If it doesn’t work, double-check:
- Your WAN IP is correct (confirm via Network > Interfaces)
- The NAT rule is enabled and has the right source/destination settings
- The firewall rule is allowing the traffic
- The external target IP is actually accepting SSH connections
备注:内容来源于stack exchange,提问作者Tedison

