News: This forum is now permanently frozen.
Pages: [1]
Topic: Is NAT possible without using DHCP?  (Read 2026 times)
« on: July 21, 2008, 20:00:49 »
redfadmin *
Posts: 3

Basically the subject says it all. I've got a DHCP server that I want to keep using. My current 3COM firewall has no problem with NAT when it has DHCP turned off. However, it seems the only way I can get outside the monowall is to let monowall do DHCP. I've got a public address on WAN and private on LAN. With or without DHCP I can access the monowall admin page with its private address. Monowall itself can ping or tracert anything on the internet.
« Reply #1 on: July 21, 2008, 20:31:03 »
ChainSaw
Guest

can your clients access the Internet if you use an IP address rather than a host name?

http://208.69.32.231/   (www.google.com)

CS...
« Reply #2 on: July 21, 2008, 21:57:32 »
redfadmin *
Posts: 3

To answer CS, no.

I was hoping it wouldn't get complicated but it is.
I got NAT to work without DHCP by using the monowall IP as the default gateway on the client. With my current firewall I can use either 1) a switch IP inside the monowall (LAN side that does VLANing/routing), 2) the firewall IP, or 3) the router IP that sits on the WAN side of the firewall as the default gateway. Currently I am using the switch as the clients' gateway and would prefer to get monowall to accept that as I have a number of devices with IP configured manual/static.
Does this seem possible? Or do I have to change my DHCP server and all my static devices to use the monowall as the gateway? I really don't want to do that because I've still got 1:1 NAT and the DMZ to test and this could drag out to a long process that may or may not work for me in the end.
Thanks for any help on this.
« Reply #3 on: July 22, 2008, 16:16:15 »
redfadmin *
Posts: 3

A little more info.
I have 3 NICs, an onboard Broadcom Gigabit, a 3COM 3C905B, and a D-Link cheapo. I thought the issue might be something to do with promiscuous mode. I tried every combination of card in the WAN and LAN positions. In all cases monowall can tracert (by host name) fine but a workstation can only ping or tracert (by IP or name) past the monowall by using the monowall itself as the gateway.
« Reply #4 on: July 26, 2008, 22:15:36 »
cmb *****
Posts: 851

If the only way it works is with DHCP it sounds like you're misconfiguring something when not using DHCP. IP, subnet mask, gateway, and/or DNS.
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines