DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
DMZ not working correctly in Dual WAN mode? (2820n)
- wywywywy
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 19
- Thank you received: 0
17 Jun 2010 10:53 #62394
by wywywywy
DMZ not working correctly in Dual WAN mode? (2820n) was created by wywywywy
Hi all,
Basically this is my network config,
- 2820n
- WAN1 = ADSL with 6 static public IPs
- WAN2 = ADSL (different ISP) with a separate router, ethernet connection
- 10 PCs in the network
- 5 of the PCs (PC ABCDE) are DMZs, each mapped to 1 public IP on WAN1
- 4 of the PCs (PC FGHI) go to the remaining IP (main IP) on WAN1, as defined in Load Balance Policy
- 1 of the PCs (PC J) use WAN2, as defined in Load Balance Policy
- All PCs are set to use OpenDNS's DNS servers
Now the problem... the PCs FGHI and J work fine, and using the correct WAN and public IP, probably because they are not DMZs. However, PCs ABCDE show very inconsistent results - sometimes they will work for a few minutes, then suddenly they will lose Internet connectivity (LAN is fine) for a while, then back on for a few seconds, then down for another while, etc. It is totally weird.
So, is this a known problem with the "multi WAN + DMZ" combo?
And is there any further diagnostics I can do to determine the underlying problem?
Any help appreciated!!
Many thanks.
EDIT:
Or it might be a problem with the way I set up the Load Balance Policies. The manual is hopeless in this particular section. Anyone any idea on how to set them up correctly please?
Basically this is my network config,
- 2820n
- WAN1 = ADSL with 6 static public IPs
- WAN2 = ADSL (different ISP) with a separate router, ethernet connection
- 10 PCs in the network
- 5 of the PCs (PC ABCDE) are DMZs, each mapped to 1 public IP on WAN1
- 4 of the PCs (PC FGHI) go to the remaining IP (main IP) on WAN1, as defined in Load Balance Policy
- 1 of the PCs (PC J) use WAN2, as defined in Load Balance Policy
- All PCs are set to use OpenDNS's DNS servers
Now the problem... the PCs FGHI and J work fine, and using the correct WAN and public IP, probably because they are not DMZs. However, PCs ABCDE show very inconsistent results - sometimes they will work for a few minutes, then suddenly they will lose Internet connectivity (LAN is fine) for a while, then back on for a few seconds, then down for another while, etc. It is totally weird.
So, is this a known problem with the "multi WAN + DMZ" combo?
And is there any further diagnostics I can do to determine the underlying problem?
Any help appreciated!!
Many thanks.
EDIT:
Or it might be a problem with the way I set up the Load Balance Policies. The manual is hopeless in this particular section. Anyone any idea on how to set them up correctly please?
Please Log in or Create an account to join the conversation.
- wywywywy
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 19
- Thank you received: 0
17 Jun 2010 11:01 #62395
by wywywywy
Replied by wywywywy on topic DMZ not working correctly in Dual WAN mode? (2820n)
Would also like to mention that, as soon as I disable WAN2, the PCs ABCDE work perfectly straightaway.
Please Log in or Create an account to join the conversation.
- wywywywy
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 19
- Thank you received: 0
02 Jul 2010 11:46 #62643
by wywywywy
Replied by wywywywy on topic DMZ not working correctly in Dual WAN mode? (2820n)
In case anyone is interested, the problem was to do with my Load Balancing Policy setup.
Barry from support, who has been extremely helpful, sent me this link which explains the Load Balancing Policy setup screen. (The screen is confusing and not user friendly in my opinion.)
http://draytek.com/user/SupportAppnotes.php?Id=73
So everything is resolved now.
Thanks.
Barry from support, who has been extremely helpful, sent me this link which explains the Load Balancing Policy setup screen. (The screen is confusing and not user friendly in my opinion.)
So everything is resolved now.
Thanks.
Please Log in or Create an account to join the conversation.
- mehuge
- Offline
- Junior Member
Less
More
- Posts: 18
- Thank you received: 0
26 Jul 2010 11:54 #62996
by mehuge
Replied by mehuge on topic DMZ not working correctly in Dual WAN mode? (2820n)
So what was wrong with your particular configuration and what did you do to fix it?
I have a similar problem, in that a PC mapped to a DMZ IP, 1/2 it's outbound internet connections don't work, 1/2 do. Basically, if the router auto load balances them out WAN2 they don't work, if they go out of WAN1 they do work.
Other non-DMZ hosts don't have a problem.
I worked around it by setting up a policy to direct all the DMZ hosts traffic out of WAN1, so it no longer is affected by auto load balancing, but why should it not be able to take advantage of the load balancing?
Only incoming connections on it's external IP need to be forced down WAN1 outbound connections should be able to use either WAN1 or WAN2.
I have a similar problem, in that a PC mapped to a DMZ IP, 1/2 it's outbound internet connections don't work, 1/2 do. Basically, if the router auto load balances them out WAN2 they don't work, if they go out of WAN1 they do work.
Other non-DMZ hosts don't have a problem.
I worked around it by setting up a policy to direct all the DMZ hosts traffic out of WAN1, so it no longer is affected by auto load balancing, but why should it not be able to take advantage of the load balancing?
Only incoming connections on it's external IP need to be forced down WAN1 outbound connections should be able to use either WAN1 or WAN2.
Please Log in or Create an account to join the conversation.
- wywywywy
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 19
- Thank you received: 0
26 Jul 2010 12:26 #62997
by wywywywy
Replied by wywywywy on topic DMZ not working correctly in Dual WAN mode? (2820n)
Basically I misunderstood the screens, and put values into the Destination columns which I shouldn't have. Now I have values into the Source columns, but left the Destination columns and the Ports columns blank, and load balancing works perfectly.
Have to use OpenDNS on each machine instead of relying on the router's DNS server though.
Have to use OpenDNS on each machine instead of relying on the router's DNS server though.
Please Log in or Create an account to join the conversation.
Moderators: Chris, Sami
Copyright © 2024 DrayTek