Orbi WiFi 7 RBE973
Reply

Configuring 1-1 NAT on FVS336GV2

JRV
Aspirant
Aspirant

Configuring 1-1 NAT on FVS336GV2

Thought I had this figured out, but it's not working.

I have 5 public IPs: x.x.x.153-157
I have 3 mail servers: 10.200.10.2-4

WAN Mode is NAT, and I've set up an inbound SMTP rule as follows:

Service: SMTP
Action: ALLOW always

Send to LAN Server: Address Range
Start: 10.200.10.2
Finish: 10.200.10.4

WAN Destination IP Address: Address Range
Start: x.x.x.153
Finish: x.x.x.155

WAN1 is set to x.x.x.153 with subnet & gateway per ISP. I can ping .153, but not .154 or .155.

All servers work (individually) with single-server port forwarding, none work with 1-1.

Double-checked external DNS; all correct.

Am I missing a setting or something?

Message 1 of 7
JRV
Aspirant
Aspirant

Re: Configuring 1-1 NAT on FVS336GV2

I should add that I can ping .153, but not .154 or .155, and TELNET [IP] 25 fails to connect for all 3. Further, when I configure WAN to LAN logging in the router, I see no connections when I try to Telnet to 25 on any of the 3 IPs.
Message 2 of 7
jmizoguchi
Virtuoso

Re: Configuring 1-1 NAT on FVS336GV2

make sure your ISP does not block port 25
Message 3 of 7
adit
Mentor

Re: Configuring 1-1 NAT on FVS336GV2

Create a individual rule for each public IP and test.
Message 4 of 7
JRV
Aspirant
Aspirant

Re: Configuring 1-1 NAT on FVS336GV2

Thanks for your replies.

THis is a business-class ISP. They do not block TCP25; have been using that for years with a single server on .153, one of the 3 IPs I'm now attempting to use with 1-1.

Forwarding works fine with single-server rules--likewise, have used that all along. The problem only occurs with 1-1 NAT rules.

One thing I noticed when setting it back to single-server rules...if I just disable the 1-1 Rules and enable the single-server Rules, the routing table still shows 1-1 Rules, and the single-server inbound Rules didn't work; had no inbound connectivity. Outbound (all outbound permitted) was OK.

So I gather that "disable," in NetGear-speak, means leave the routing table modified for the rules created, but block connections.

I didn't look at the routing table when I had 1-1 set up, but I guess what this tells me is that the routing table is a mess when you have both sets of rules in place, even though only 1 set (either single-server or 1-1) is enabled. Does that sound correct? IOW, I need to delete--not just disable--the Inbound rules that are not relevant to the 1-1 scenario?

I'll try it next opportunity. But meantime, if you can confirm my observations, I'll try it with a lot more confidence!
Message 5 of 7
JRV
Aspirant
Aspirant

Re: Configuring 1-1 NAT on FVS336GV2

Tried it...still not working.

Is there something I need to do to put the router in 1-1 "mode", other than just create Rules that use address ranges?
Message 6 of 7
jmizoguchi
Virtuoso

Re: Configuring 1-1 NAT on FVS336GV2

Classical mode over NAT
Message 7 of 7
Top Contributors
Discussion stats
  • 6 replies
  • 12735 views
  • 0 kudos
  • 3 in conversation
Announcements