I do have a destination NAT rule that redirects SSH on the WAN interface to a git server (WAN TCP/22 to an internal server on port TCP/222). The looks here sounds like the SSH directly to the firewall (NOT on the WAN interface) is also getting wrapped up in this destination NAT rule.
I can confirm after disabling that NAT rule I am able to successfully SSH to the firewall.
So the issue here is that the NAT rules are matching and processing the SSH traffic meant for the firewall. It looks like the NAT rule is ignoring the interface the traffic is coming in on.
Breakdown of the rule:
-- Interface: ZN_WAN (group with WAN1 and WAN2 interfaces)
-- Version: IPv4+IPv6
-- Protocol: TCP
-- Destination Address: This firewall
-- Destination Port: TCP/22
-- Redirect Target IP: Git server
-- Redirect Target Port: 222
I'll continue to mess with the rule to make it more specific to only the WAN IPs, but this is a change is how the NAT rules are processed from 26.7.1
I can confirm after disabling that NAT rule I am able to successfully SSH to the firewall.
So the issue here is that the NAT rules are matching and processing the SSH traffic meant for the firewall. It looks like the NAT rule is ignoring the interface the traffic is coming in on.
Breakdown of the rule:
-- Interface: ZN_WAN (group with WAN1 and WAN2 interfaces)
-- Version: IPv4+IPv6
-- Protocol: TCP
-- Destination Address: This firewall
-- Destination Port: TCP/22
-- Redirect Target IP: Git server
-- Redirect Target Port: 222
I'll continue to mess with the rule to make it more specific to only the WAN IPs, but this is a change is how the NAT rules are processed from 26.7.1
"