• April 19, 2024, 08:21:03 PM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: dfl800 port forwarding -but can only get to sites from the internet not from lan  (Read 6098 times)

andrew.keating

  • Level 1 Member
  • *
  • Posts: 10

i have set up 2 port forwarding configs to web servers, this is working fine - from the internet - but not from the lan

i have sat, nat and allow action


1      site1_sat      SAT      any      all-nets      core      site1-ext_ip      https
2     site1_nat       NAT     lan              lannet     any             all-nets            https
3     site1_allow     Allow     any         all-nets     core     site1-ext_ip     https

1      site2_sat      SAT      any      all-nets      any      site2-ext_ip     https
2     site2_nat       NAT     lan             lannet     any             all-nets         https
3     site2_allow     Allow     any             all-nets     any             site2ext_ip    https

any ideas what i got wrong in my config
Logged

Fatman

  • Level 9 Member
  • ****
  • Posts: 1675

I don't think this is our problem, but let's try to be more selective with our IP rules.

WAN_LAN_Group/all-nets/core/site1-ext_IP
lan/lannet/core/site1-ext_ip

would have been sufficient.

Do we have any relevant log entries?

If we turn on logging on all of these rules do we get relevant log entries?

Does your server see the SYN inbound, and if so from/to what address and port?
Logged
non progredi est regredi

andrew.keating

  • Level 1 Member
  • *
  • Posts: 10

in the logging i see conn_open_natsat from my source ip - desktop on the lan - to the external facing ip
then nothing
Logged

andrew.keating

  • Level 1 Member
  • *
  • Posts: 10

ok, then a    conn_close_natsat a little later

what i did notice was that the site2 request logs a site1_nat rule in the log - so something is messed up, site1 request also logs site1_nat
Logged

andrew.keating

  • Level 1 Member
  • *
  • Posts: 10

but neither site1 nor site2 work
Logged

danilovav

  • Level 4 Member
  • ****
  • Posts: 424
  • Alexandr Danilov

Forget using of "any" in IP rules.

Correct port mapping (work from inside too) seems like below

# external
SAT wan/all-nets core/wan_ip yourservice (SAT: new destination = yourprivatehost)
Allow wan/all-nets core/wan_ip yourservice
# internal
SAT lan/lannet core/wan_ip yourservice (SAT: new destination = yourprivatehost)
NAT lan/lannet core/wan_ip yourservice
Logged
BR, Alexandr Danilov

andrew.keating

  • Level 1 Member
  • *
  • Posts: 10

I just tried you recommendation - but it stopped working from the inside and the outside with that configuration!
Logged

danilovav

  • Level 4 Member
  • ****
  • Posts: 424
  • Alexandr Danilov

Does DFL specified as default gateway on private host?
Logged
BR, Alexandr Danilov

andrew.keating

  • Level 1 Member
  • *
  • Posts: 10

yes - dfl is the gateway on the lan.
Logged

andrew.keating

  • Level 1 Member
  • *
  • Posts: 10

Is that an issue?  It is the default gateway for the LAN, we don't have another one.
Logged

danilovav

  • Level 4 Member
  • ****
  • Posts: 424
  • Alexandr Danilov

To find out the reason of problem, enable logging of rules created - it will show you if it's working. Next, see Status > Connections and Status > Logging during test accessing.
Logged
BR, Alexandr Danilov