IX. NAT Related Features

Configuring non-NAT operation (public subnet) with a Vigor 3900 / 2960

Vigor 2960
Vigor 3900
IP Routing
Public IP
Routed Subnet

If you have multiple public IP addresses (i.e. a subnet allocated by your ISP as opposed to just a single IP address), it is possible to configure the DrayTek units that support multiple IP's in a flexible way using NAT, Multi-NAT/WAN IP Alias and IP Routing. The preferred method is often to use WAN IP Alias to minimise the direct exposure from unsolicitied incoming traffic via NAT but a non-NAT configure can also be setup.

Using IP Routing, IP Addresses can be routed directly through to the LAN side directly without applying NAT to that traffic, which can be useful for placing servers or other devices behind the router; This configuration would mean that the device uses a public IP Address directly.

IP Routing can be used in addition to the WAN IP Alias feature, but IP addresses allocated as IP Aliases are removed from the pool of addresses usable by the IP routed subnet.

This guide will use as the Network Address, with a subnet mask, which has a usable IP range of to
The router will use for the WAN interface.
The address will be used for IP routing, clients on the network would use an IP address available in the usable range, with as their gateway.

On the Vigor 3900 series, this requires:

  • Configuring the WAN interface as normal
  • Set up a LAN interface in Routed mode, either as a part of an existing NAT subnet or as a separate Routed network interface
  • Set up the router's LAN/WAN ARP Proxy feature to link the LAN and WAN interfaces

There are two methods to set this up:

Dedicated LAN Interface - This uses a separate LAN interface in Routing mode to route the public IP addresses through, this requires either a dedicated LAN port on the router or the use of VLAN tags (on a separate switch)

NAT & Routed Shared LAN Interface - This would add the routed subnet to the existing NATted LAN interface, this is required if the devices will be on the same physical network and VLAN tags are not in use

NAT & Routed Shared LAN Interface

The WAN interface will need to be configured first of all, in this example, the router is using as its WAN IP address, this is configured from WAN > General Setup by selecting and Editing the relevant WAN interface.

This example also has specified as an Alias IP, which can be used for port forwarding. This removes that IP address from the IP addresses available on the public subnet because it is effectively in use by the router.

This method requires temporarily disabling the WAN interface from the Global tab of that WAN interface's configuration. Once that is done, click Apply to apply the changes.

The LAN interface then needs to be configured with the additional routed interface. This is done from the LAN - General Setup section by editing the existing LAN profile. Scroll down to the More Subnet section and click Add. Enter the IP address to use; in this example we use, the Subnet Mask must also be specified to match what the ISP has provided.

Set the Mode of the additional subnet to ROUTING mode and enable or disable DHCP depending on your requirements (with this implementation, it's recommended to leave DHCP disabled). Make sure that the Start IP and End IP addresses reflect the available range.

Click the Save button once that's configured, then click Apply to save and apply that change.

The WAN interface can be re-enabled at this point:

With the WAN and LAN interfaces configured, the router now needs the IP Routing configured to link them - this is configured from Routing - Static Route - LAN/WAN Proxy ARP.

Click the Add button on there to create a new entry:

In the pop-up window, set the name to reflect which network it links to, link the WAN interface, in this case wan1 to the LAN interface with the routed subnet configured, in this case lan1. Enter the IP address that the router will be using for the IP Routed subnet, set the subnet mask and click Apply on that to apply it.

With that configured, the router will then be able to route traffic directly to devices configured with the public subnet range and using the router's address as the gateway address.

How do you rate this article?

1 1 1 1 1 1 1 1 1 1