DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
multiple vlans access to internal server via public ip
- palych
- Topic Author
- Offline
- New Member
Less
More
- Posts: 6
- Thank you received: 0
17 Jun 2013 12:09 #76644
by palych
multiple vlans access to internal server via public ip was created by palych
Dear All
i have 2 subnets set up 192.168.10.x and 192.168.15.x for example
i have a server on subnet 192.168.10.x with ip address 192.168.10.10 for example
did port forwarding to it so i can connect to it by typinghttp://service.domain.com:4567 from outside and it works fine
I do not want the subnets to see each other internally - one is the "secure internal" subnet and the other one is guest subnet so from within guest network i dont want to be able to see any devices on the main subnet, but would like guests to be able to typehttp://service.domain.com:4567 and have access as if they were outside
at the moment all i get is page can not be displayed...
by the way - have multi-static IP config and the router is Vigor 2850
is this achievable?
i have 2 subnets set up 192.168.10.x and 192.168.15.x for example
i have a server on subnet 192.168.10.x with ip address 192.168.10.10 for example
did port forwarding to it so i can connect to it by typing
I do not want the subnets to see each other internally - one is the "secure internal" subnet and the other one is guest subnet so from within guest network i dont want to be able to see any devices on the main subnet, but would like guests to be able to type
at the moment all i get is page can not be displayed...
by the way - have multi-static IP config and the router is Vigor 2850
is this achievable?
Please Log in or Create an account to join the conversation.
- voodle
- Offline
- Big Contributor
Less
More
- Posts: 1139
- Thank you received: 0
17 Jun 2013 12:38 #76648
by voodle
Replied by voodle on topic Re: multiple vlans access to internal server via public ip
Does the DNS server give the local or public IP when queried internally?
That should work I think, you'd need to have inter-lan routing between the subnets enabled potentially and also make sure you're on the newest 3.6.4 firmware.
That should work I think, you'd need to have inter-lan routing between the subnets enabled potentially and also make sure you're on the newest 3.6.4 firmware.
Please Log in or Create an account to join the conversation.
- palych
- Topic Author
- Offline
- New Member
Less
More
- Posts: 6
- Thank you received: 0
17 Jun 2013 15:52 #76655
by palych
Replied by palych on topic Re: multiple vlans access to internal server via public ip
but if i do inter lan routing, wouldn't I open access to local ip range?
i want both lans to work as if they were separate networks connected to different IP's and having a link via internet only (sort of) so i can only access forwarded
ports to certain internal addresses
i hope it makes sense
I even tried to dohttp://ipaddress:4567 but still get page can not be displayed so it is more a routing issue by the looks of it
i want both lans to work as if they were separate networks connected to different IP's and having a link via internet only (sort of) so i can only access forwarded
ports to certain internal addresses
i hope it makes sense
I even tried to do
Please Log in or Create an account to join the conversation.
- voodle
- Offline
- Big Contributor
Less
More
- Posts: 1139
- Thank you received: 0
17 Jun 2013 22:11 #76665
by voodle
Replied by voodle on topic Re: multiple vlans access to internal server via public ip
If the DNS resolves as an internal address with your server then yes, you'd need to use inter-lan routing, if they resolve as the public IP internally then yes, that should work without inter-LAN routing enabled and it would indicate some problem with NAT loopback.
Please Log in or Create an account to join the conversation.
- palych
- Topic Author
- Offline
- New Member
Less
More
- Posts: 6
- Thank you received: 0
18 Jun 2013 20:01 #76676
by palych
Replied by palych on topic Re: multiple vlans access to internal server via public ip
but how would i troubleshoot NAT loopback?...
Please Log in or Create an account to join the conversation.
- voodle
- Offline
- Big Contributor
Less
More
- Posts: 1139
- Thank you received: 0
18 Jun 2013 21:01 #76680
by voodle
Replied by voodle on topic Re: multiple vlans access to internal server via public ip
make sure Join NAT IP Pool is unticked for the alias IP if that's what you're doing, make sure that address is resolving as the public IP when doing a DNS lookup from the client PCs you're testing with.
update the firmware, if that doesn't fix it then report it as a bug to suppport
update the firmware, if that doesn't fix it then report it as a bug to suppport
Please Log in or Create an account to join the conversation.
Moderators: Chris, Sami
Copyright © 2024 DrayTek