Static routes not working in this setup unless
All Replies
-
Hi @PeterUK
Thank you for sharing your configuration file.
After reviewing it, we found that this situation is because the WLAN type is set to external. When configured this way, outbound packets are NATed to that interface by default.
As a result, when return traffic hits the second static route, it gets NATed to 192.168.254.1. This means the overall packet flow to the FLEX 200 will be: Internet → 192.168.254.1 instead of the AP IP 192.168.253.1, preventing it from reaching the AP client. This is why you said that the static route is not working.
You have two potential solutions:
- Set a policy route to allow returning packets to SNAT to NONE, which aligns with your current configuration.
- Change the WLAN type to internal by modifying the configuration as follows:
/vrf "main" interface ethernet "WLAN" "type" "external" ➡ /vrf "main" interface ethernet "WLAN" "type" "internal"
Kay
Share your feedback through our survey, make your voice heard, and win a WiFi 7 AP!
0 -
But now try with Ge6 WLAN as internal and you see you have to set next hop to auto
PM sent with changes
so If I set routing rules to gateway IP to 192.168.254.2 for the return traffic then it works too but my question is should I need this routing rules for return traffic when static routes should/might that care of it?
0 -
Hi @PeterUK
Based on your current configuration, everything appears to be correct, and the overall flow is set to NAT first, then routing. At the moment, we can’t think of any further issues that might arise.
If possible, please also capture packets on ge6 interface.
Kay
Share your feedback through our survey, make your voice heard, and win a WiFi 7 AP!
0 -
Well I was just unsure about the return traffic needing the routing rule but I guess its just needed when you do two hops instead of one for Static routes to works.
So all good now thanks
1
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 144 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.6K Security
- 237 USG FLEX H Series
- 267 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.3K Consumer Product
- 247 Service & License
- 384 News and Release
- 83 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.2K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight