USG 310 - public IP behind PPPoE
how to correctly configure public IP behind PPPoE with dynamic IP? This is my configuration withou public IP:
! model: ZyWALL 310
! firmware version: 4.70(AAAB.0)
!
interface-name ge1 wan1
interface-name ppp0 wanTvinet
account pppoe TVINET
user ***
encrypted-password ***
authentication chap-pap
compression no
idle 0
!
interface wan1
type external
description TVINET VDSL
upstream 10000
downstream 50000
mtu 1500
ping-check default-gateway method icmp period 30 timeout 5 fail-tolerance 5 probe-condition any
no ping-check activate
ip address 0.0.0.0 0.0.0.0
!
interface vlan848
port wan1
vlan-id 848
description TVINET_VLAN_848
ip address dhcp metric 0
upstream 1048576
downstream 1048576
mtu 1500
type external
ip rip send version 2
ip rip receive version 2
ip ospf priority 1
ip ospf cost 10
!
interface wanTvinet
bind vlan848
description PPPoE TVINET
connectivity nail-up
account TVINET
metric 0
upstream 1048576
downstream 1048576
mtu 1492
ipv6 nd ra accept
!
Connection itself works fine, but I need to set the public IP - according to my ISP, they routed my public IP behind the dynamic IP address received on wanTvinet interface. Now I am not sure, where to set the public IP?Accepted Solution
-
Hi @Lukas
Please help to log a ticket, so we can do a deeper Packet-Trace analysis and assist you:
https://support.zyxel.eu/hc/en-us/requests/new?ticket_form_id=114093996354
Regards,
Tobias0
All Replies
-
Hi,
you may use a SNAT in Policy Routing to send out WAN Traffic with Public IP from your ISP.
https://support.zyxel.eu/hc/en-us/articles/360001440613-Policy-Routes-USG-VPN-ATP-Different-scenario-usages-configurations
If you need to configure it on Dial-In, then these are the steps:
https://support.zyxel.eu/hc/en-us/articles/360005190500-Instructions-for-setting-up-a-hardware-ZyWALL-USG-series-gateway-using-a-static-IP-address-for-connecting-to-the-Internet
Kind Regards,
Tobias0 -
Hi @Zyxel_Tobias,
Thank you for your answer.
I know how to configure pulic IP on direct ethernet connections, but I am not sure where to put public IP in this situation - on wan1 or vlan848? First thing I need to test is simple PING from Internet. I have tried to set the public IP on wan1 and then on vlan848 interface, but the PING did not work (even with temporary disabled firewall).
0 -
Hi Lukas,
on WAN1 should be fine, VLAN is only the Dial-in linking object here.
Regards,
Tobias0 -
Thank you, @Zyxel_Tobias
I have put public IP (withou gateway - ISP did not privede any gateway) to the wan1 interface:interface wan1type externaldescription TVINET VDSLupstream 10000downstream 50000mtu 1500ping-check default-gateway method icmp period 30 timeout 5 fail-tolerance 5 probe-condition anyno ping-check activateip address *.*.*.* 255.255.255.254!
I have temporary disabled firewall, but the ping from outside is not working. Ping from LAN side is working fine. What else should I check, so that the ping from outside Internet is working?0 -
Hi @Lukas
Please help to log a ticket, so we can do a deeper Packet-Trace analysis and assist you:
https://support.zyxel.eu/hc/en-us/requests/new?ticket_form_id=114093996354
Regards,
Tobias0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 144 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.6K Security
- 238 USG FLEX H Series
- 267 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.3K Consumer Product
- 247 Service & License
- 384 News and Release
- 83 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.2K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight