DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

2910 NAT broken?

  • snowch
  • Topic Author
  • Offline
  • New Member
  • New Member
More
19 May 2009 15:08 #55870 by snowch
2910 NAT broken? was created by snowch
I am trying to setup NAT for http on my 2910.

I have tried port redirection and open ports to the same server, however neither work. When I run nmap from an external machine to my ext interface, it is showing the ports as filtered. If I access the private address internally on http, the web server is fine.

I am stumped on this one???

Any ideas?

Many thanks in advance,

Chris

Please Log in or Create an account to join the conversation.

  • snowch
  • Topic Author
  • Offline
  • New Member
  • New Member
More
19 May 2009 15:21 #55871 by snowch
Replied by snowch on topic 2910 NAT broken?
Using wireshark to watch the traffic between the draytek and the destination, it looks as though NAT is not rewriting the source ip address of the incoming tcp packets.

Please Log in or Create an account to join the conversation.

More
19 May 2009 17:16 #55872 by runningdeere
Replied by runningdeere on topic 2910 NAT broken?
Make sure you have changed the default management port for http on the router. You need to change it to something other than 80 - say 8080 or 8888
But make sure you put :port (ie :8888) on the end of the url when you try to access it[/b]

Please Log in or Create an account to join the conversation.

  • snowch
  • Topic Author
  • Offline
  • New Member
  • New Member
More
19 May 2009 19:03 #55875 by snowch
Replied by snowch on topic 2910 NAT broken?
Hi runningdeere,

I had changed the management ports and the network traffic is getting through the external interface. The problem seems to be that the IP header for the src field is not NAT'd by the draytek, and is going through to my private network unchanged.

Many thanks,

Chris

Please Log in or Create an account to join the conversation.

  • snowch
  • Topic Author
  • Offline
  • New Member
  • New Member
More
20 May 2009 10:28 #55895 by snowch
Replied by snowch on topic 2910 NAT broken?
Could the problem be that the host I am natting to has a default gw different that is another router (i.e. not the draytek doing the natting)?

For this to work, the draytek doing the nat would need to do SNAT (which it appears that it is not doing?

Any ideas?

Many thanks,

Chris

Please Log in or Create an account to join the conversation.

Moderators: ChrisSami