I believe there are several threads on this without a solution. Chiming in here:
I have a server in a DMZ VLAN exposing HTTPS over DNAT, including loopback and reflexive NAT rules. The XG18 firewall has an xxx.myfirewall.co dynamic DNS registration. Accessing this HTTPS service on this hostname from WAN to the DMZ works fine.
However, accessing the HTTPS service on this hostname from another VLAN to the DMZ does not work. In the log, you can see the loopback NAT rule triggering, but the traffic being blocked by a final "drop all" rule. A higher-priority rule allowing HTTPS traffic from this VLAN to the DMZ is not triggered.
Workaround is creating a manual DNS entry for xxx.myfirewall.co to the DMZ internal IP address, of course having LAN clients use the XG18 DNS server als resolver.
This was functional on MR1 but no longer after upgrading to MR3. The old trick of "opening NAT rule, saving again" does not work.
This thread was automatically locked due to age.