WAN and 2 VLANs - How to configure route?

Options

Hi,

my ISP told me to setup an WAN Interface with another VLANs on it. The WAN-Interface (i dont need to setup a vlan) is for internet only. On the WAN Interface i have to configure a second Interface with a vlan id 2222. This one is for voip only. I can not reach the internet from vlan2222!

As you can see here i setup a vlan 2222 on the wan2 interface and after i connect i get the ip from my isp 10.8.x.x

The wan interface works fine. My clients run on vlan80. I have setup no special route. i use the firewall settings to allow or denie access from a vlan to wan or to other vlans. This works for me great.

My problem:

I have setup a new vlan 299 for testing purpose. I like to connect an ip phone to a port mapped to vlan299. And i need to route all VOIP-traffic over vlan2222 and all internet traffic over WAN. But i dont know how to setup this kind of route.

Can somebody help?

All Replies

  • PeterUK
    PeterUK Posts: 2,749  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    edited October 2023
    Options

    Your AP need to be setup for VLAN299 to work also VLAN299 is disabled

    Have you set a zone for VLAN2222 and VLAN299? to allow by firewall?

    You may need routing rule too

  • Maik20
    Maik20 Posts: 6
    First Comment
    Options

    Yes i need to activate the vlan 299, there is a firewall rule to allow access from 299 to 2222.

    But what kind of rule?

    I need to rules:

    route all INTERNET traffic from 299 to WAN2

    route all VOIP traffic from 299 to VLAN2222

    But how can i decide what kind of traffic it is? For example my ip phone needs internet to download updates. But the voip network from my isp dont provide internet access so i can not route permanent from 299 to 2222

  • PeterUK
    PeterUK Posts: 2,749  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    Thats a bit tricky I don't know of a ISP that does that but you likely don't need VLAN299 then

    you need to add a zone for VLAN2222 and set it on the VLAN2222 on WAN2

    On routing you can do

    incoming VLAN80

    next hop VLAN2222

    You then need to work out what the traffic for VOIP-traffic is by capturing packets when in use then to the above rule add service ports this will be for VOIP-traffic

    firewall rule from VLAN80 to VLAN2222

    add another routing rule below that rule

    On routing you can do

    incoming VLAN80

    next hop WAN

    this will be for internet

  • WJS
    WJS Posts: 132  Ally Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    I think no additional route needed. Just check you have allowed policy, and check IP from voip do the source NAT.

    So capture packets on WAN2 to check if traffic reach to or check any drop logs?

  • Maik20
    Maik20 Posts: 6
    First Comment
    Options

    Thanks i give it a try. How can i capture packets on WAN2. I have an older Zyxel Zywall USG 200

  • Zyxel_Kevin
    Zyxel_Kevin Posts: 764  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    Hi @Maik20,

    Greeting forum, Please kindly provide your config file by Private message.

    Thank you

Security Highlight