There is a huge mixup here. ZS is NATing everything going out of interface ETH00 and you are trying to NAT some VLANs on interface ETH01. Firstly make sure which interface is the outside and then remove the general NAT that ZS does on interface ETH00.
I guess I am confused on how to make ZS view my ETH00 as the wan port, and make ETH01, ETH01.20, ETH01.30 and ETH01.70 NAT’d behind ETH00, and how to make ETH01.74 and ETH01.90 not NAT’d……
How should my Router>NAT page look like? I have had ETH00 in the “NAT Enabled Interfaces”, that’s when everything appears to be NAT’d and I have had ETH01, ETH01.20, ETH01.30 and ETH01.70 in there leaving ETH00 out….
Not sure what I am doing wrong.