Hi,
I am trying to make both wan interfaces work om my DFL-800 the way I want - respond to port forwarded traffic on allowed ports on both wan interfaces. As it is now I can only get WAN1 to respond in the manor that I would like to.
First an explanation of the context: WAN1 and WAN2 both receive their IP settings via DHCP. My ISP allows me to be able to receive up to five IP-adresses this way and the interfaces usually will have the same
gateway and
subnets (wan1_gw and wan2_gw are the same) but that is not something that I will take for granted.
The setup I am trying is the classic "drawkcaB routing table" approach and treat it as I have statically assigned ip:s on WAN1 and WAN2 and different ISPs.
Routing table
wan2:
Interface | Network | Gateway | Local IP address | Metric |
wan2 | wan2net | | | 100 |
wan2 | all-nets | wan2_gw | | 100 |
Routing Rule
wan2_routing:
# | Name | Source interface | Source network | Destination interface | Destination network | Service |
1 | wan2_routing | wan2 | all-nets | core | wan2_ip | all_tcpudpicmp |
Forward Table:
mainReturn Table:
wan2 (routing table above)
My
main table looks like this:
Interface | Network | Gateway | Local IP address | Metric | Monitor this route |
wan1 | wan1net | | | 100 | No |
wan1 | all-nets | wan1_gw | | 100 | No |
dmz | dmznet | | | 100 | No |
lan | lannet | | | 100 | No |
I have allow and SAT rules (and a general NAT rule even if I am not sure it has any purpose in this case) for the traffic I would like to be able to resond to on WAN2:
SAT_http_wan2_mail2 | SAT | any | all-nets | core | wan2_ip | http |
NAT | NAT | lan | lannet | any | all-nets | all_tcpudpicmp |
Allow_http_wan2 | Allow | any | all-nets | core | wan2_ip | http |
When I enable more extensive logging on these rules and try to connect via http on the WAN2 interface there is
conn_open entry but then something goes wrong and the connection times out and I am not able to tell what it is (the same server is also SAT:ed on WAN1 and there it works just fine). I have a hunch that it is something with the return traffic that is not working but I can not figure it out.
I have tried many different configs but this is the one that seems most logical. Am I going about this the wrong way? Is there a clear error in my config above? Should this even work? Any pointers will be appreciated since I am about to give up.
data:image/s3,"s3://crabby-images/af375/af37530eb8a4d267fa3946a57cdbd261da5e4286" alt="Smiley :)"
Best Regards
Anders