Dual WAN Rules / Internal Server routing.
-
Some assistance would be marvellous from those greater than I.
WAN1 -PPPOE (DYNAMIC ADDRESS) (Default Gateway)
WAN2 -PPPOE (DYNAMIC ADDRESS)Duckdns dynamic update on both WAN adapters.
DEST1LAN - SERVER 1 (192.25.25.1) PORT 12345 DUCKDNS URL https://duckdns.xyz1.com/server1
DEST2LAN - SERVER 2 (192.50.50.1) PORT 12345 DUCKDNS URL https://duckdns.xyz2.com/server2
NGINX (192.168.10.1)
ANTICIPATED PATHWAY
WAN1 > NGINX > SERVER 1
WAN2 > NGINX > SERVER 2The nginx locations are set to redirect to servers in NGINX machine. If I use the Duckdns WAN1 address I can reach both servers by changing the urls. I cannot however access the SERVER2 via WAN2 address.
Have been playing with this for a while now and conceded to asking for help. Almost certainly something fundamental but some form of assistance would be brilliant. Dual WAN is not something I have configured a lot and this particular configuration is proving a little tricky to nail.
Note I have taken NGINX machine out of the equation and tried a port forward direct to SERVER2 via WAN2. I simply cannot reach the SERVER2 machine via WAN2. WAN1 / SERVER1 no issues at all.
Thanks to all reading this. Any other information required then please do ask.
-
This post is deleted! -
@zoqask
If you're on CE 2.5.1 you propably ran into this issue: Port forward works only on interface with default gateway, does not work for alternative wans (CE Only) -
Thanks @viragomann that does make some sense as I have had this similar layout working on dual wan using the older version. Bit of a blow for me, but in fairness the netgate team have many requests a month so not sure on the lead time to a bug fix.
-
@zoqask
There are some threads here regarding this. I think, I've read, that this will not be solved in 2.5.x.
So you can either rollback to 2.5.0 or go with 2.6 snapshot to solve. -
@viragomann this home dev / concept. Not had a need for a this scheme in production. Shame I cant route in dual wan. Will have to opt for dual server over single WAN for now. Pfsense is a great product and I really cannot expect every angle to be covered. Kudos to the netgate team.
P.s But would be great for this to be resolved soon. :)