Virtual Server (NAT) Not work with 2 Active WAN Links

Virtual Server (NAT) Not work with 2 Active WAN Links

Virtual Server (NAT) Not work with 2 Active WAN Links
Virtual Server (NAT) Not work with 2 Active WAN Links
2024-05-23 03:29:21 - last edited 3 weeks ago
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.2.4_20240119-rel44368

I have a set up with 2 WANs and internal LAN. 

 

1. Out of the 2 WAN links one (WAN/LAN1) gets a fixed public IP over PPPoE and the port is configured accordingly for direct negotiation with ISP on the load balancer.

2. The other WAN comes via another router forwarding a static private IP to the WAN port of ER605 over ethernet which is configured with a static IP with from the private subnet.

3. On virtual server - http / https and ssh is forwarded from WAN/LAN1 to a reserved static ip (assigned by ER605 IP reservation) hosted on an internal server.

 

All redirection, while accessing the public IP from the Internet (outside internal LAN) works when only  WAN/LAN1 (which is redirected) link is active and the other WAN is down. It does not work when both the WAN links are active.

 

The same configuration used to work with TL R407 load balancer which had 100 mbps ports.

 

Any suggestion would be much appreciated.

  0      
  0      
#1
Options
4 Reply
Re:Virtual Server (NAT) Not work with 2 Active WAN Links
2024-05-23 08:11:55

Hi @hizibiz 

Thanks for posting in our business forum.

Please be specific about the symptom you have with the router while the second WAN is active.

Have you considered that the other WAN may be using HTTP, HTTPS, and SSH causing a problem in accessing the 80 443, and 22? This is a generic ask because I don't know what symptoms and behavior you experienced on the router.

I expect to see more details about your specific setup and configs on this port forwarding and second WAN.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting Manual ★ ☚ (Disclaimer: Short links are used above solely for guidance to TP-Link subdomains and are safe and tracker-free. Exercise caution with short links from non-official members on forums. We are not liable for external content or damage from non-official members' link use.)
  0  
  0  
#2
Options
Re:Virtual Server (NAT) Not work with 2 Active WAN Links
3 weeks ago

  @Clive_A  Here is short network diagram

 

With 2 active WAN connections, attempt to access the public IP on WAN/LAN1 port over http / https / ssh from external network times out. 

 

The same connection attempt perfectly works ( response 200 for http / https and login prompt for ssh ) when WAN1 is down / disconnected. By works means, the connection gets DNAT'd to the IP reserved host (on private IP subnet which has all internal hosts) with http / https / ssh open.

 

WAN1 is a path to another router terminating a fibre connection over another private subnet. It does not have any other host.

 

The same config perfectly work for TL407.

  0  
  0  
#3
Options
Re:Virtual Server (NAT) Not work with 2 Active WAN Links
3 weeks ago - last edited 3 weeks ago

Hi @hizibiz 

Thanks for posting in our business forum.

hizibiz wrote

  @Clive_A  Here is short network diagram

 

With 2 active WAN connections, attempt to access the public IP on WAN/LAN1 port over http / https / ssh from external network times out. 

 

The same connection attempt perfectly works ( response 200 for http / https and login prompt for ssh ) when WAN1 is down / disconnected. By works means, the connection gets DNAT'd to the IP reserved host (on private IP subnet which has all internal hosts) with http / https / ssh open.

 

WAN1 is a path to another router terminating a fibre connection over another private subnet. It does not have any other host.

 

The same config perfectly work for TL407.

Can you upload a backup of your file of ER605? Get a .txt with your username and password and your backup in one compressed package. Zip them and use the email address you registered on our forum as the password. I need to reproduce this with our test team.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting Manual ★ ☚ (Disclaimer: Short links are used above solely for guidance to TP-Link subdomains and are safe and tracker-free. Exercise caution with short links from non-official members on forums. We are not liable for external content or damage from non-official members' link use.)
  1  
  1  
#4
Options
Re:Virtual Server (NAT) Not work with 2 Active WAN Links
Friday

Hi @hizibiz

This case is closed due to no further replies.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting Manual ★ ☚ (Disclaimer: Short links are used above solely for guidance to TP-Link subdomains and are safe and tracker-free. Exercise caution with short links from non-official members on forums. We are not liable for external content or damage from non-official members' link use.)
  0  
  0  
#5
Options

Information

Helpful: 0

Views: 216

Replies: 4

Related Articles