• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Interface Routing? (2xLAN 2xWAN)

Scheduled Pinned Locked Moved Routing and Multi WAN
4 Posts 4 Posters 1.4k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • W
    WooPigStewie
    last edited by Jul 30, 2013, 9:38 PM Jul 30, 2013, 9:34 PM

    My apologies, but I am not sure what the correct term is for what I am looking for:

    I am currently running 3 interfaces.  LAN and WAN plus OPT1 which is used for a private intranet.  I am using static routing to send traffic addressed to our remote subnets out the OPT1 interface.  Now I need to add a 4th interface to handle untrusted/guest wireless access.  I want to make sure that any traffic on that interface is forced out the WAN connection and does not get routed across the OPT1 private intranet…  I thought this would be policy based routing, but I cannot seem to get that to work.  Am I on the right track?  And if not, what should I be looking at to acomplish this?

    Thanks in advance!

    1 Reply Last reply Reply Quote 0
    • S
      Supermule Banned
      last edited by Jul 30, 2013, 9:48 PM

      Use manual outbound nat and block access to the OPT1 interface.

      1 Reply Last reply Reply Quote 0
      • P
        phil.davis
        last edited by Jul 31, 2013, 2:08 AM

        I guess everything on LAN and across OPT1 is private intranet IPs, which you don't want GuestNet to reach. It seems that GuestNet can use the default routing to get to the real internet, so you won't need any policy-based routing rules.
        Make an alias for all your private intranet address space - name like PrivateInternal, then put a block rule on GuestNet for destination PrivateInternal.
        I think Automatic Outbound NAT will see that GuestNet is a "normal" LAN and add outbound NAT rules on WAN "underneath" for you.

        As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
        If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

        1 Reply Last reply Reply Quote 0
        • K
          kathampy
          last edited by Jul 31, 2013, 3:03 PM Jul 31, 2013, 3:02 PM

          Create a rule on OPT2:
          From: *
          To: Not OPT1 subnet
          Gateway: WAN gateway

          This should be the only rule that allows Internet access.

          1 Reply Last reply Reply Quote 0
          4 out of 4
          • First post
            4/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received