Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Rules complementing static routes

    Scheduled Pinned Locked Moved Routing and Multi WAN
    2 Posts 2 Posters 408 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • senseivitaS
      senseivita
      last edited by

      I've been trying to do this:
      0_1541406149741_static routing downstream.png

      Getting the network upstream to communicate with a host or even the whole subnet down the line without NAT. I know the static rule's good, it makes sense, but it's the firewall rules on the inner firewall, to allow the traffic in, those can't get to work. Against better judgement I even tried a * to * rule and still it wouldn't work.

      I also tried using as destination the upstream interface's address (172.16.18.10 here above in my example doodles) on the middle router but that sort of would be NATting, don't it? Didn't work anyway; maybe because I didn't actually did the port translation rules, only the firewall rules.

      Any advice? :)

      Missing something? Word endings, maybe? I included a free puzzle in this msg if you solv--okay, I'm lying. It's dyslexia, makes me do that, sorry! Just finish the word; they're rarely misspelled, just incomplete. Yeah-yeah-I know. Same thing.

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        Give us an example of traffic that you are trying to pass here, actual source and destination IPs.

        It seems likely that the traffic is not hitting the outer firewall at all.

        Alternatively the target may not be using that as route back if the source is a public address.

        Run packet captures. See what traffic is actually arriving on which interfaces.

        Steve

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.