Allow Lan2 to access Lan1 webserver

Options
Tim_
Tim_ Posts: 2
First Anniversary
Hello,

I have problems with browsing from lan2 to lan1. At the moment the webrequest needs 4-5 seconds te reply, and browsing to local server is very slow.

browsing from LAN1 to server goes fast.

Current setup USG40W
Lan1 IP range 192.168.0.X  (Server IP 192.168.0.4 website HTTP port 80) Acces to WAN
DNS : 192.168.0.4, second DNS 8.8.8.8

Lan 2 IP range 192.168.1.X (No acces to WAN allowed)
DNS : 192.168.0.4, second DNS 8.8.8.8

Lan3 IP range 192.168.2.X (FYI)

Current configuration :



The strange thing is, if i modify the IP4V destination of 'Lan2_server' to any, then it works fast. But then i have internet access on lan2 and i don't want that. 

If i modify it again to lan1_subnet it keeps fast browsing until the computer on lan2 reboots. 

Do i have to alllow a extra Policy? Or a routing?


All Replies

  • mMontana
    mMontana Posts: 1,302  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options
    Remember that rules are applied as order.
    Any rule "hit" automatically exclude subsequent.
  • PeterUK
    PeterUK Posts: 2,749  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    I think you need a from LAN2 to Zywall for DNS


  • WJS
    WJS Posts: 132  Ally Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options
    choose LAN1 as dst zone instead of any(Exclude Zywall..) on "LAN2_Server" policy ?
  • Tim_
    Tim_ Posts: 2
    First Anniversary
    Options
    Hello all, 

    Thanks for the suggestions.

    i changed the order of the policy. (no better  result,see picture)
    i changed the Lan2 to Lan1_subnet as destination (no better result)
    I changed the DNS of Lan2 to Zywal, second server, tirth google (no better result)




  • Zyxel_Kevin
    Zyxel_Kevin Posts: 764  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options
    Hi @Tim_ ,
    Could we confirm the problem quickly remotely ?
    Please send the remote information in Private Message if you are avaliable
    Kevin

Security Highlight