News: This forum is now permanently frozen.
Pages: [1]
Topic: Overlapping NAT  (Read 3433 times)
« on: March 30, 2007, 01:34:24 »
Miles *
Posts: 4

Hi all,

I don't know if what I want to do is possible, but here it is:

- I have a single device on the LAN port of a Soekris/m0n0wall box - a Sony videoconferencing codec @ 192.168.1.2. The Soekris interface is at 192.168.1.1

- The Soekris is connected to two networks:
a) WAN port @10.198.135.249 (a private WAN)
b) OPT1 port @207.x.x.x public internet

I would like users (other codecs) to be able to access the Sony from either the public internet (via OPT1) or from the private WAN (via WAN). Basically, users on the WAN would enter 10.198.135.248 to go through the firewall to get to the Sony (at 192.168.1.2) and users on the internet would enter 207.x.x.x to get to the same place. Does that make any sense?

When I tried to set up two 1:1 NATs, the box copmplains that they overlap on the LAN portion since both NATs point to 192.168.1.2. Unfortunately, I can't multihome the Sony.

At the same time, I do not want the m0n0wall to bridge the two networks (private WAN and public internet) for security reasons.

Any suggestions?

Thanks in advance,

Miles
« Reply #1 on: March 30, 2007, 04:29:46 »
Miles *
Posts: 4

Should I just set up port forwards instead of NAT??

Miles
« Reply #2 on: March 31, 2007, 21:01:25 »
cmb *****
Posts: 851

Yeah, you don't want 1:1, you can only 1:1 a specific device once (regardless of firewall) by definition of 1:1. You can open a port on as many IP's as you desire using port forwards/inbound and server NAT.
« Reply #3 on: April 03, 2007, 00:51:25 »
Miles *
Posts: 4

OK thanks, I seem to be on the right track. I can now access the Sony from devices on the WAN network, however the OPT1 side doesn't work (even though the hits are showing up in the Firewall log).

I can set up the WAN interface with IP/Netmask/Gateway but the OPT1 port has no gateway options. Is there a reason why this is so? There is the "bridge with" option, but I'm not sure how that will affect the rules I have set up for NAT (as soon as you tell the port to bridge with LAN, all the IP settings go gray).

What should I do next?

Thanks,

Miles
« Reply #4 on: April 04, 2007, 01:46:23 »
cmb *****
Posts: 851

WAN needs to be your Internet connection. You can only put a default gateway on WAN, and you'll need that to be on your Internet link. You'll have to setup static routes for the subnets across your private WAN link.
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines