ROUTING

Posts: 13  Freshman Member
First Comment Fourth Anniversary

Good morning,
I have an ATP200 with a vlan/dmz to which I connected a NAS that must be reached on the external IPs of the two WANs for the services on ports 80 443 and 10001, I created the NAT rules and the security policies I needed, from outside it works correctly! If I try to reach the device on one of the public addresses of the WANs connected with a PC from the lan or the vlan, it is unreachable.
Which rule should I create?
Thanks

Welcome!

It looks like you're new here. If you want to get involved, click on this button!
«1

All Replies

  • Posts: 3,761  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    Sounds like NAT loopback? make sure its enabled for your NAT rule.

    You then need a policy rule from LAN1 to DMZ

  • Posts: 13  Freshman Member
    First Comment Fourth Anniversary
    Screenshot 2024-11-17 alle 15.40.27.png

    loopback is active

    Screenshot 2024-11-17 alle 16.10.32.png

    i create policy, but not found internal

  • Posts: 3,761  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    check logs for blocked traffic

  • Posts: 13  Freshman Member
    First Comment Fourth Anniversary

    I have no blocks in the log regarding this route

  • Posts: 3,761  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    Disable the firewall for a quick check.

    So to be clear you go from LAN2 to the WAN IP to loopback to DS1618v IP?

  • Posts: 13  Freshman Member
    First Comment Fourth Anniversary
    Screenshot 2024-11-18 alle 17.20.18.png

    Do you mean disable security policies? It doesn't work anyway...

  • Posts: 3,761  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited November 2024

    Does your ATP get the WAN IP's not rfc1918 IP's?

  • Posts: 13  Freshman Member
    First Comment Fourth Anniversary

    My addresses are all public static

    WAN2

    Screenshot 2024-11-19 alle 13.59.26.png

    WAN1_PPP

    Screenshot 2024-11-19 alle 14.00.36.png

    WAN1

    Screenshot 2024-11-19 alle 14.02.54.png


    port 10001 on these IPs is reachable without restrictions for testing

  • Posts: 3,761  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited November 2024

    I'm not sure why you can't loopback then sorry

    You can do a packet capture on the interface DMZ as you try connecting to it by WAN IP from LAN to see if its getting to the NAS

  • Posts: 13  Freshman Member
    First Comment Fourth Anniversary

    I have enabled packet cutting for DMZ

    Screenshot 2024-11-19 alle 23.34.43.png

    I then tried to access the NAS from the LAN from the WAN with its two IP

    Screenshot 2024-11-19 alle 23.34.58.png Screenshot 2024-11-19 alle 23.35.10.png

    But the firewall doesn't even generate log files

    Screenshot 2024-11-19 alle 23.35.31.png

Welcome!

It looks like you're new here. If you want to get involved, click on this button!

Welcome!

It looks like you're new here. If you want to get involved, click on this button!