ROUTING

LMitc
LMitc Posts: 8  Freshman Member
First Comment Fourth Anniversary

Good morning,
I have an ATP200 with a vlan/dmz to which I connected a NAS that must be reached on the external IPs of the two WANs for the services on ports 80 443 and 10001, I created the NAT rules and the security policies I needed, from outside it works correctly! If I try to reach the device on one of the public addresses of the WANs connected with a PC from the lan or the vlan, it is unreachable.
Which rule should I create?
Thanks

«1

All Replies

  • PeterUK
    PeterUK Posts: 3,387  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    Sounds like NAT loopback? make sure its enabled for your NAT rule.

    You then need a policy rule from LAN1 to DMZ

  • LMitc
    LMitc Posts: 8  Freshman Member
    First Comment Fourth Anniversary

    loopback is active

    i create policy, but not found internal

  • PeterUK
    PeterUK Posts: 3,387  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    check logs for blocked traffic

  • LMitc
    LMitc Posts: 8  Freshman Member
    First Comment Fourth Anniversary

    I have no blocks in the log regarding this route

  • PeterUK
    PeterUK Posts: 3,387  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    Disable the firewall for a quick check.

    So to be clear you go from LAN2 to the WAN IP to loopback to DS1618v IP?

  • LMitc
    LMitc Posts: 8  Freshman Member
    First Comment Fourth Anniversary

    Do you mean disable security policies? It doesn't work anyway...

  • PeterUK
    PeterUK Posts: 3,387  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited November 18

    Does your ATP get the WAN IP's not rfc1918 IP's?

  • LMitc
    LMitc Posts: 8  Freshman Member
    First Comment Fourth Anniversary

    My addresses are all public static

    WAN2

    WAN1_PPP

    WAN1


    port 10001 on these IPs is reachable without restrictions for testing

  • PeterUK
    PeterUK Posts: 3,387  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited November 19

    I'm not sure why you can't loopback then sorry

    You can do a packet capture on the interface DMZ as you try connecting to it by WAN IP from LAN to see if its getting to the NAS

  • LMitc
    LMitc Posts: 8  Freshman Member
    First Comment Fourth Anniversary

    I have enabled packet cutting for DMZ

    I then tried to access the NAS from the LAN from the WAN with its two IP

    But the firewall doesn't even generate log files

Security Highlight