DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

PASS THROUGH

  • daven2411
  • Topic Author
  • Offline
  • New Member
  • New Member
More
05 Dec 2019 11:48 #1 by daven2411
PASS THROUGH was created by daven2411
I am new to DrayTek equipement. I have a 2762n with a Watchguard Filewall behind it. I want to forward all traffic that comes into the DrayTek to the Watchguard and it will do the filtering/forwarding.
The DrayTek is 192.168.0.1, the WatchGuard is 192.168.0.2 and my internal network is 192.168.70.0/24. Please can someone advise on how I forward all traffic to the Watchguard Firewall?

Please Log in or Create an account to join the conversation.

  • ajrichards27
  • User
  • User
More
05 Dec 2019 16:16 #2 by ajrichards27
Replied by ajrichards27 on topic Re: PASS THROUGH
Hi Daven,

Any reason why you haven't chosen something like a Draytek 130 modem rather than a firewall? WIth the set up as is, you will be double NATing which can cause complications - but here goes.

First click "VPN and Remote Access", then "Remote Access Control" and untick all of those.

In NAT, click open ports, then click on one of the index numbers to create a new rule.
Enable the open port rule, give it a comment (name), select all WANs, input the private IP of 192.168.0.2, then for port 1, input start port of 1, and end port of 65535, leave with protocol TCP/UDP. Click ok and apply and that will do for most of it.

When applying the rule you may get a warning of a conflict - this will be with the management ports (See System Maintenance, management section) and the SSL VPN port, see SSL VPN, general section.
If you do get this warning you need to adjust the open port rule to dodge those that are in use in management, and SSLVPN. Alternatively you can adjust the management ports to all be at the end of the port list, so set telnet to 65535, then HTTP to 65534, HTTPS to 65533, FTP to 65532, TR069 to 65531, SSH to 65530. Then go to SSLVPN and set to port 65529. Once you''ve done that repeat the open port rule above, but use an end port of 65528.

That'll do it, and has worked well for me in the past. Any issues then i would personally just buy a Draytek 130 modem, its what its designed for :)

Please Log in or Create an account to join the conversation.