Comments
-
But it seems to be related to DNS issues of the Zywall itself. The device SELF is not able to reach any public dns. So you might check if that is working ok for your device..
-
No unfortunately not.. Still not working. We will switch to different hardware.
-
Hi Jeff, I have provided you the conf file in a pm. Thanks
-
Hi, Yes we do SNAT on multiple WAN IP's. Using policy route
-
No Bridge setup.
-
Hi PeterUK, Yes, an external interface is connected: ISP Fiber -> BaseT switch. IPoE setup on WAN2 interface of Zywall with fixed IP. A traceroute. It seems it does route via the ISP gateway. Then at hob 30 it stops.
-
Hi again, would there be no need for a change in vpn-tunnel configuration? I'm thinking of the vpn "Local policy": We only can add one subnet, not multiple subnets like i described above. Will this work with only a policy route on both ends?
-
Hi Emily, thank you for answering. The other end of the tunnel is not a Zyxel device, i'm not sure what vpn-setup they have. But i the way you illustrate should be straight forward. We will have a look and report back.
-
Above issue nr1: has been solved by creating a Policy Route specifically for the NAT rules created for port forwarding. The default Policy route is in use for outbound traffic SNAT and caused to translate that traffic with our own Public IP. Maybe @Zyxel_Stanley can clarify further?
-
Hi Charlie, 1) It is running v4.33 firmware. 2) I will make the screenshots for you later. 3) I see it mentioned outbound traffic, but of course it is inbound traffic.. So all traffic coming from internet, via Dnat rule forwarded to NAS at tcp 8080
-
Hello (Charlie), the configuration has been working for the past few weeks now. With a slight change in config. There also was a policy route necessary for outgoing trafic. But that's not why i'm asking for help. Main problems we currently have are: 1) Incoming outbound (DNAT-rule) traffic to a specific device (NAS-ftp…
-
Thanks for the info Charlie. Will test the setup this way. There is one more issue: The Zywall is connected to the fiber-switch from isp (Alcatel OS6250-8m) This switch has 2 combo 1000baseT ports, one is connected to te Zywall to provide 500mb up/down internet-connection. The Zywall only shows a link speed of 100mb while…
-
Hi Charlie, There is only 1 physical link from the wan-port of the Zywall to the ISP-gateway (fiber switch). The IP 145.54.x.x is only a "numbered link" the ISP uses to NAT our public subnet 77.60.x.x/29 they say.. So only 1 interface should be used i think. The funny thing is, if you look at the provided Cisco example…