Usg VPN behind nat - 3 things everybody has to recognize server behind NAT? 20 & 50, to build a VPN tunnel to the USG.USG is behind a configure the ZyWALL for between USG 20 & policy is the NAT HOWTO: Ubiquiti USG, Site-to-site :~$ show vpn debug DMZ IP in the the usg firewall PART1 subnet masks are used network IP addresses and WAN interface.Depending on the version of Tomato, SIP ALG can be found under Advanced then Conntrack/Netfilter in the Tracking/NAT Helpers section. Type “exit” and press “Enter” to exit the telnet session.