DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Hairpin NAT / NAT Loopback / NAT Reflection

  • cwager990
  • Topic Author
  • User is blocked
  • User is blocked
More
11 Feb 2019 03:52 #1 by cwager990
I am using a Draytek Vigor 2860,

Firmware: 3.8.9.3_BT

I can not get Hairpin NAT to work no matter what I do in spite of the fact that the Draytek Site, says this is supported.

I have setup port redirection and I can access the web server externally, Internally I can access it with its LAN IP, but if I try to Access it using the Public IP nothing.

I have no idea why this will not work and I have wasted hours trying to get it to.

Please Log in or Create an account to join the conversation.

More
11 Feb 2019 07:08 #2 by x64
From my experience with a 2862.I've had significant issues some of which involve NAT loopback.

Consider the following possibilities.
Default firewall rule set to BLOCK might affect reverse NAT include NAT loopback I found that I'ls impossible to write a rule to 're-allow' the traffic. (This WAS an issue for me in 2.8.9.2_BT- not sure if it was fixed in 3.8.9.3_BT). In the 2862 this does seem better in 3.9.0_BT. I worked around this by leaving the rule to allow and writing explicit f/w rules to block other traffic (in addition of course to rules to allow the traffic I wanted to pass)

Interaction of Use of multiple external IP addresses, IP Aliases to support them, and IP routed subnet (to a separate network LAN definition), alongside 'normal' NAT. The underlying issue remains even to 3.9.0_BT on the 2862. With the IP routed subnet configuration, NAT loopback from a device behind NAT on the default IP could not access a device published behind reverse NAT on an alias.

Please Log in or Create an account to join the conversation.

  • cwager990
  • Topic Author
  • User is blocked
  • User is blocked
More
11 Feb 2019 11:40 #3 by cwager990
Replied by cwager990 on topic Re: Hairpin NAT / NAT Loopback / NAT Reflection

x64 wrote: From my experience with a 2862.I've had significant issues some of which involve NAT loopback.

Consider the following possibilities.
Default firewall rule set to BLOCK might affect reverse NAT include NAT loopback I found that I'ls impossible to write a rule to 're-allow' the traffic. (This WAS an issue for me in 2.8.9.2_BT- not sure if it was fixed in 3.8.9.3_BT). In the 2862 this does seem better in 3.9.0_BT. I worked around this by leaving the rule to allow and writing explicit f/w rules to block other traffic (in addition of course to rules to allow the traffic I wanted to pass)

Interaction of Use of multiple external IP addresses, IP Aliases to support them, and IP routed subnet (to a separate network LAN definition), alongside 'normal' NAT. The underlying issue remains even to 3.9.0_BT on the 2862. With the IP routed subnet configuration, NAT loopback from a device behind NAT on the default IP could not access a device published behind reverse NAT on an alias.



Okay, well that made some difference as you said I changed the default rule to pass, and then WAN > LAN Block if not further matches with all my allow rules below.

LOOPBACK now works for the main WAN IP Address but as you say not for any of the VIP's regardless of weather they are in the nat pool or not, is this the point at which I raise a support request with draytek? this was an expensive router that can not do something most basic models can do, really makes me mad.

Please Log in or Create an account to join the conversation.

More
11 Feb 2019 12:01 #4 by piste basher
Replied by piste basher on topic Re: Hairpin NAT / NAT Loopback / NAT Reflection
A couple of years ago I had issues with NAT loopback no longer working - fixed after contacting support who sent me a beta firmware, subsequently OK when full version released as well. No need to mess with firewall rules.

I suggest it's worth opening a ticket.

Please Log in or Create an account to join the conversation.

  • cwager990
  • Topic Author
  • User is blocked
  • User is blocked
More
11 Feb 2019 12:11 #5 by cwager990
Replied by cwager990 on topic Re: Hairpin NAT / NAT Loopback / NAT Reflection

Piste Basher wrote: A couple of years ago I had issues with NAT loopback no longer working - fixed after contacting support who sent me a beta firmware, subsequently OK when full version released as well. No need to mess with firewall rules.

I suggest it's worth opening a ticket.



Since I am using the latest firmware I find it hard to believe that his is an issue that has only just reappeared?

Please Log in or Create an account to join the conversation.

  • hopkins35
  • User
  • User
More
11 Feb 2019 13:43 #6 by hopkins35
Replied by hopkins35 on topic Re: Hairpin NAT / NAT Loopback / NAT Reflection
See my post(s) https://forum.draytek.co.uk/viewtopic.php?f=2&t=22442#p92242 in a topic that initially started talking about IPv6.

Support never fixed my NAT problems on a 2862 with multiple WAN IP aliases, I ended up selling it

Please Log in or Create an account to join the conversation.