Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Problem with incoming traffic on second WAN interface

    Scheduled Pinned Locked Moved Routing and Multi WAN
    2 Posts 2 Posters 887 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • I Offline
      imcfarla
      last edited by

      I have a setup with 2 WAN connections
      WAN is the default gateway
      OPT1 is the secondary WAN connection.

      Port 443 is Nat'd on both interfaces to the same ip address
      I have an Interface group with both WAN and OPT1 setup with all my firewall rules set on there for incoming connections

      When I try to connect to WAN:443 it works fine when I try to connect to OPT1:443 it fails.

      If I do a packet capture I can see traffic coming in on the OPT1 interface but no outgoing traffic.
      However on the WAN interface I can see traffic going out with the OPT1 address stamped on it - this is obviously wrong but I have no idea how to fix it.

      Outbound NAT is currently set to automatic.

      Any ideas?

      1 Reply Last reply Reply Quote 0
      • P Offline
        pcklinika
        last edited by

        @imcfarla:

        I have a setup with 2 WAN connections
        WAN is the default gateway
        OPT1 is the secondary WAN connection.

        Port 443 is Nat'd on both interfaces to the same ip address
        I have an Interface group with both WAN and OPT1 setup with all my firewall rules set on there for incoming connections

        When I try to connect to WAN:443 it works fine when I try to connect to OPT1:443 it fails.

        If I do a packet capture I can see traffic coming in on the OPT1 interface but no outgoing traffic.
        However on the WAN interface I can see traffic going out with the OPT1 address stamped on it - this is obviously wrong but I have no idea how to fix it.

        Outbound NAT is currently set to automatic.

        Any ideas?

        1. Add to your Local Server additional IP (IP1: 192.168.1.10 and add IP2:192.168.1.11)
        2. Set to Advanced Outbound NAT
        3. Add a rule for Source 192.168.1.11/32 (second Server IP) to use OPT1 as Translated adress
        4. Move this rule above Auto created rule for LAN to WAN

        Do NOT forget to set a NAT rule for OPT interface

        Regards,

        Andrej

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.