Double NAT?

Home Page Forums Network Management ZeroShell Double NAT?

This topic contains 11 replies, has 0 voices, and was last updated by  netsysadmin 10 years, 1 month ago.

Viewing 13 posts - 1 through 13 (of 13 total)
  • Author
    Posts
  • #41520

    netsysadmin
    Member

    Hi,

    I have the following setup:
    Internet<


    >ADSL modem/router<
    >ZeroShell<
    >LAN

    The ADSL modem/router already does NAT.
    Is it possible for ZeroShell to forward outgoing packets to the Internet via the ADSL modem/router without doing NAT on them, ie, only do routing/forwarding?

    Thank you

    #47709

    ppalias
    Member

    Go to
    Network -> Router -> NAT
    Remove the interface that connects to the modem-router from the NAT Enabled Interface list.

    #47710

    netsysadmin
    Member

    It does not work. As soon as I re-add the interface to the list of “NAT Enabled Interfaces”, it works again!

    #47711

    netsysadmin
    Member

    Any one can help?

    Thanks

    #47712

    bbozo
    Member

    1. check if ZS and adsl router are in the same subnet (they should be).
    2. ZS Should have adsl routers IP as a Default Gateway (PCs in lan should have ZS as their GTW)
    3. DNS forwarders in ZS should be set to adsl router
    4. disable NAT in ZS

    I can’t be certain this is a solution. This is in general.
    you sholud post more info on your configuration.

    #47713

    netsysadmin
    Member

    Thanks for replying.

    LAN computers use 10.0.0.0/16 subnet and have 10.0.0.3 as their gateway.
    ZeroShell LAN interface IP address: 10.0.0.3/16
    ZeroShell WAN interface IP address: 10.1.0.1/16
    ZeroShell gateway: 10.1.0.3
    ADSL modem/router LAN interface IP address: 10.1.0.3

    #47714

    bbozo
    Member

    then considering everythig a alredy said you should add in your adsl router a static route to your lan subnet and set next hop (gtw) as 10.1.0.1/16 (your ZS)

    as i can see you have a big network since you use class B subnet (16).
    Consider the ability of your adsl router and hardware you run ZS on because it can slow down your network. If you network is not that big (more than 250 clients) you should use C class subnet (24).

    hope this helps

    #47715

    ppalias
    Member

    @netsysadmin wrote:

    It does not work. As soon as I re-add the interface to the list of “NAT Enabled Interfaces”, it works again!

    For what reason you re-add it? You need to remove it from the NAT Enabled Interfaces list.

    #47716

    yuti
    Member

    I think ZS in Bridge mode may help you.

    #47717

    netsysadmin
    Member

    OK. It’s working. I think adding the static route was the solution.

    However, I am unable to ping the LAN interface (10.1.0.3) of the ADSL modem/router from a PC on the LAN!
    I can ping the WAN interface of the ZeroShell firewall (10.1.0.1).

    But I can access the internet without any problem!

    #47718

    ppalias
    Member

    Does the modem have a static route for the 10.0.0.0/16 subnet? If not, it cannot communicate with your LAN clients and you need to install a static route on the modem for 10.0.0.0/16 via 10.1.0.1

    #47719

    netsysadmin
    Member

    Yes, it does. But, I’m still unable to ping it!

    #47720

    ppalias
    Member

    If routing is ok, then you need to check any firewall that might be blocking your traffic.

Viewing 13 posts - 1 through 13 (of 13 total)

You must be logged in to reply to this topic.