News: This forum is now permanently frozen.
Pages: [1]
Topic: m0n0wall works fine with multiple WAN IPs but ping fail  (Read 2503 times)
« on: August 02, 2013, 20:06:42 »
StefanKittel *
Posts: 3

Hello,

I have a cosmetic problem.

I run m0n0wall on a VM in a datacenter.
Simple 10.0.0.0 internal network and 20 IPv4 Adresses on the WAN side. Several Port Forwardings.

Everything works fine!

Here's the problem.
I can ping only the main WAN IPv4 Adress from the WAN side.
When I ping the other WAN IPv4 Adresse I get an answer from the Main IPv4 Adress that the host can not be reached.

Any Ideas?

Quote
Ping wird ausgeführt für 46.38.227.78 mit 32 Bytes Daten:
Antwort von 46.38.227.99: Zielhost nicht erreichbar.

Stefan
« Reply #1 on: August 02, 2013, 22:28:38 »
Lee Sharp *****
Posts: 517

Have you allowed and forwarded ICMP?  Note that ICMP can only be forwarded with 1 to 1 NAT.
« Reply #2 on: August 03, 2013, 12:01:10 »
StefanKittel *
Posts: 3

Have you allowed and forwarded ICMP?  Note that ICMP can only be forwarded with 1 to 1 NAT.

Hello,

think so, these are my first two rules on WAN
*    RFC 1918 networks    *    *    *    Block private networks
ICMP    *    *    *    *    PING 

This is my only rule on LAN
    *    LAN net    *    *    *    Default LAN -> any 

Stefan
« Reply #3 on: August 04, 2013, 00:22:06 »
Lee Sharp *****
Posts: 517

So, that will allow you to ping the WAN IP.  Now how are you resolving the other IP addresses?  Are you using 1 to 1 NAT?
« Reply #4 on: August 04, 2013, 22:02:20 »
StefanKittel *
Posts: 3

So, that will allow you to ping the WAN IP.  Now how are you resolving the other IP addresses?  Are you using 1 to 1 NAT?

Hello,

I entered the others IPs on the "Server NAT" because these are single IPs no ranges.

Stefan
« Reply #5 on: August 05, 2013, 01:09:48 »
Lee Sharp *****
Posts: 517

OK.  The firewall is the gate, but NAT is the road.  For ping to work, you have to NAT icmp, as well as TCP/IP.  But 1 to 1 NAT is the only way I know to do that.  Server based NAT is 1 to many, and it has no way of knowing where to send ICMP.
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines