Allow Lan2 to access Lan1 webserver

Tim_
Tim_ Posts: 2
First Anniversary
Hello,

I have problems with browsing from lan2 to lan1. At the moment the webrequest needs 4-5 seconds te reply, and browsing to local server is very slow.

browsing from LAN1 to server goes fast.

Current setup USG40W
Lan1 IP range 192.168.0.X  (Server IP 192.168.0.4 website HTTP port 80) Acces to WAN
DNS : 192.168.0.4, second DNS 8.8.8.8

Lan 2 IP range 192.168.1.X (No acces to WAN allowed)
DNS : 192.168.0.4, second DNS 8.8.8.8

Lan3 IP range 192.168.2.X (FYI)

Current configuration :



The strange thing is, if i modify the IP4V destination of 'Lan2_server' to any, then it works fast. But then i have internet access on lan2 and i don't want that. 

If i modify it again to lan1_subnet it keeps fast browsing until the computer on lan2 reboots. 

Do i have to alllow a extra Policy? Or a routing?


All Replies

  • mMontana
    mMontana Posts: 1,389  Guru Member
    50 Answers 1000 Comments Friend Collector Fifth Anniversary
    Remember that rules are applied as order.
    Any rule "hit" automatically exclude subsequent.
  • PeterUK
    PeterUK Posts: 3,461  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    I think you need a from LAN2 to Zywall for DNS


  • WJS
    WJS Posts: 156  Master Member
    5 Answers First Comment Friend Collector Third Anniversary
    choose LAN1 as dst zone instead of any(Exclude Zywall..) on "LAN2_Server" policy ?
  • Tim_
    Tim_ Posts: 2
    First Anniversary
    Hello all, 

    Thanks for the suggestions.

    i changed the order of the policy. (no better  result,see picture)
    i changed the Lan2 to Lan1_subnet as destination (no better result)
    I changed the DNS of Lan2 to Zywal, second server, tirth google (no better result)




  • Zyxel_Kevin
    Zyxel_Kevin Posts: 892  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 500 Comments
    Hi @Tim_ ,
    Could we confirm the problem quickly remotely ?
    Please send the remote information in Private Message if you are avaliable
    Kevin