News: This forum is now permanently frozen.
Pages: [1]
Topic: Internet doesn't work when I do 1:1 NAT  (Read 2018 times)
« on: July 17, 2007, 23:47:53 »
laserline *
Posts: 7

I've setup m0n0wall for the first time and so far it's great!  Here's what my setup looks like.  I have 13 external static IPs.  The internet works with LAN and OPT1 which I renamed to DMZ to get my servers ready on.  When I go to one of my servers I'm setting up and access the internet all is fine until I setup the 1:1 NAT at which point the internet does not work once the setting are applied.  Anyone know why that would be the case.  Let me know if you need more info.

This is what the NAT Rule looks like:

Interface: WAN
External subnet: 2.0.0.11/32 (yes I'm using 2.0.0.0 in place of my real ip)
Internal subnet: 192.168.2.11

EDIT:  This should probably be under Firewall/NAT Category.  Maybe one of the mods can move it?  I don't want to double post.
« Last Edit: July 18, 2007, 01:12:42 by laserline »
« Reply #1 on: July 18, 2007, 07:42:47 »
cmb *****
Posts: 851

Do you have Proxy ARP enabled for the extra public IP's?
« Reply #2 on: July 18, 2007, 08:40:23 »
laserline *
Posts: 7

Quote
Do you have Proxy ARP enabled for the extra public IP's?

I've tried ones with it enabled and ones without it and the results are the same.  I don't know if this helps at all, but the only external IP I can access is the 2.0.0.0 IP.

EDIT & UPDATE:  For whatever reason it's working now.  Maybe it just needed time and a few reboots.  In any case, the problem I'm having now is that I can't ping the machine's external IP.  I can ping the private IP of 192.168.2.11, but not 2.0.0.11.  I've tried pinging from multiple computers and on different networks entirely and can't ping 2.0.0.11 or any others for that matters.  Any thought?  Oh and just fyi when I'm on computer 192.168.2.11 and go to whatismyip.org it does give me 2.0.0.11.  Thanks for your help too cmb!
« Last Edit: July 18, 2007, 22:34:40 by laserline »
« Reply #3 on: July 25, 2007, 01:32:31 »
cmb *****
Posts: 851

You have to either wait or clear ARP caches when you bring up additional IP's.

You need to add firewall rules on your WAN if you want it to respond to pings.
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines