Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    2 WANs to different vlans

    Scheduled Pinned Locked Moved Routing and Multi WAN
    13 Posts 3 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ?
      A Former User @sintei
      last edited by

      @sintei, I need more information about firewall rules and firewall logs.

      S 1 Reply Last reply Reply Quote 0
      • S
        sintei @A Former User
        last edited by

        @silence

        Ill try to write it all out:
        Under gateways I have:

        WAN_DHCP 	Default (IPv4)	WAN	78.82.x.x	78.82.x.x	Interface WAN_DHCP Gateway	 
        LANGW		LAN	dynamic	dynamic	Interface lan Gateway	   
        WEBSITESGW		WEBSITES	dynamic	dynamic	Interface lan Gateway	   
        WAN2_DHCP		WAN2	78.82.x.x	78.82.x.x	Interface WAN2_DHCP Gateway
        

        Interface assignments:

        WAN	vtnet0 (xx.xx.xx.xx.xx)
        LAN	vtnet1 (xx.xx.xx.xx.xx)
        WAN2	vtnet2 (xx.xx.xx.xx.xx)
        Websites	VLAN xx on vtnet1 - lan (WebsiteVLAN)
        

        WAN2 rules:

        States	Protocol	Source	Port	Destination	Port	Gateway	Queue	Schedule	Description	Actions
        *	RFC 1918 networks	*	*	*	*	*		Block private networks	
        *	Reserved Not assigned by IANA	*	*	*	*	*		Block bogon networks	
        IPv4 TCP/UDP	*	*	WAN2 net	443 (HTTPS)	*	none	 	Any_incoming_wan2_443	    
        IPv4 TCP/UDP	*	*	WAN2 net	80 (HTTP)	*	none	 	Any_incoming_wan2_80	    
        IPv4 *	*	*	WEBSITES net	*	*	none	 	port80allow	    
        
        

        WEBSITES rules:

        
        States	Protocol	Source	Port	Destination	Port	Gateway	Queue	Schedule	Description	Actions
        
        IPv4 *	*	*	LAN net	*	*	none	 	Block LAN	    
        		  
        IPv4 TCP/UDP	WEBSITES net	*	*	*	*	none	 	Default allow VLAN77 to any
        	
        

        I have one wordpress site. Its reachable on WAN2. But when I close down access from VLAN WEBSITES to LAN, the wordpress site looses access to gateway and can't perform checkups. It seems the gateway is located in LAN net. How do I utilize the second gateway and keep it in my subnet/VLAN?

        V 1 Reply Last reply Reply Quote 0
        • V
          viragomann @sintei
          last edited by

          @sintei said in 2 WANs to different vlans:

          LANGW LAN dynamic dynamic Interface lan Gateway
          WEBSITESGW WEBSITES dynamic dynamic Interface lan Gateway

          What are these gateways for?
          Cannot think of any reason to have a gateway on LAN in your setup.

          ? 1 Reply Last reply Reply Quote 0
          • ?
            A Former User @viragomann
            last edited by

            @viragomann I don't understand its configuration either, but if what you need is to access a host from the internet through your wan 2, why simply don't you configure a porfowaring? and in the wan rule 2 allows access!

            ? S 3 Replies Last reply Reply Quote 0
            • ?
              A Former User @A Former User
              last edited by

              @silence said in 2 WANs to different vlans:

              and in the wan rule 2 allows access!

              26a662e1-dd5d-4532-931b-391b53a1d1e6-image.png

              With this you don't have to create the rule yourself.

              1 Reply Last reply Reply Quote 0
              • S
                sintei @A Former User
                last edited by

                @silence said in 2 WANs to different vlans:

                @viragomann I don't understand its configuration either, but if what you need is to access a host from the internet through your wan 2, why simply don't you configure a porfowaring? and in the wan rule 2 allows access!

                What I'm trying to do is secure so that someone coming in via WAN2 only has access to my VLAN WEBSITES.
                And that VLAN should be isolated from my LAN and other VLANs.
                The VLAN WEBSITES is on the LAN NIC so it's somewhat tied?
                Right now I can't block the VLAN WEBSITES from accessing LAN via rule as then the website looses connectivity to internet (for instance to check updates etc).
                But I can access it FROM the internet.
                Error in chrome says: gateway timed out when trying to update SEO, Themes etc . So that's why I'm investigating this direction.

                @viragomann said in 2 WANs to different vlans:

                @sintei said in 2 WANs to different vlans:

                LANGW LAN dynamic dynamic Interface lan Gateway
                WEBSITESGW WEBSITES dynamic dynamic Interface lan Gateway

                What are these gateways for?
                Cannot think of any reason to have a gateway on LAN in your setup.

                I think I created these to try to resolve the issue. Since you say they are not needed then I will delete them.

                V 1 Reply Last reply Reply Quote 0
                • S
                  sintei @A Former User
                  last edited by

                  @silence

                  Just to clarify:
                  I can access my website via domain name in chrome.
                  It resolves and also is secured with lets encrypt certificate using HAproxy

                  ? 1 Reply Last reply Reply Quote 0
                  • ?
                    A Former User @sintei
                    last edited by

                    @sintei, Ok now we are understanding each other then the question is that your website needs to go online? to be able to update certain?

                    In this case you should check your nat rules

                    S 1 Reply Last reply Reply Quote 1
                    • S
                      sintei @A Former User
                      last edited by

                      @silence said in 2 WANs to different vlans:

                      @sintei, Ok now we are understanding each other then the question is that your website needs to go online? to be able to update certain?

                      In this case you should check your nat rules

                      Yes, exactly. The website needs to online.
                      So I checked and created some rules in NAT (tried both 1:1 and outbound) but can't get it to work either way.
                      Surely, an outbound rule should suffice?

                      ? 1 Reply Last reply Reply Quote 0
                      • ?
                        A Former User @sintei
                        last edited by

                        @sintei, publish the nat rules of your firewall.

                        and your firewall records the moment it receives the error.

                        1 Reply Last reply Reply Quote 0
                        • V
                          viragomann @sintei
                          last edited by

                          @sintei said in 2 WANs to different vlans:

                          Right now I can't block the VLAN WEBSITES from accessing LAN via rule as then the website looses connectivity to internet (for instance to check updates etc).
                          But I can access it FROM the internet.

                          The only reason for this, I can think of is that on the web server you are using a DNS server in the LAN subnet.

                          If that's not the case enable logging in the block rule and check the firewall log to see, which access from the web server to LAN is blocked.

                          S 1 Reply Last reply Reply Quote 0
                          • S
                            sintei @viragomann
                            last edited by

                            @viragomann said in 2 WANs to different vlans:

                            @sintei said in 2 WANs to different vlans:

                            Right now I can't block the VLAN WEBSITES from accessing LAN via rule as then the website looses connectivity to internet (for instance to check updates etc).
                            But I can access it FROM the internet.

                            The only reason for this, I can think of is that on the web server you are using a DNS server in the LAN subnet.

                            If that's not the case enable logging in the block rule and check the firewall log to see, which access from the web server to LAN is blocked.

                            You my dear sir are correct!
                            I could find some DNS settings and changed them manually and it worked!
                            Thanks.

                            Also, big thanks to @Silence for helping me troubleshooting this. Have a good night!

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.