Please refer here to have an overview of Drop-in mode with multiple WANs.
Please refer to the diagram from the provided link, PC’s IP will be NAT as below if traffics are going out to WAN2:-
192.168.1.x > 210.10.10.x > 22.2.2.x
So there is not an issue to publish your services over WAN2 and firewall still maintain it own public IP.
Lets say that i gave WAN2 Interface the ip address 44.33.22.6
My external DNS has the block registered 44.33.22.1 - 5 with different public host names.
how do i map the incoming traffic from ISP to reach the block 44.33.22.1 - 5 through peplink ?
do i use nat(for ISP2) on peplink ? if so, what kind of nat rules ?
My deployment is as follows.
ISP ----- PEPLINK ------ FIREWALL
when i put peplink inline, ISP 1 is Okay, ISP 2 outgoing traffic is okay when i put default gateway on firewall as Peplink but incoming from internet through ISP 2 to published servers isn’t working.
does this mean all outbound nat on firewall has to be towards ISP 1 block ? e.g 172.172.172.x in my case ?
what if i do not have enough Public ip addresses on ISP 1 block ? but i have some on my ISP 2 block, how do i use them ?
when you said “This will NAT 44.33.22.x to 172.172.172.x.” does this mean i have to put the nat mapping for
44.33.22.1, 44.33.22.2, 44.33.22.3, 44.33.22.4
on peplink to ISP block on firewall ? or i just nat interface ISP2 ip network interface address on peplink (44.33.22.6) to ISP1 network interface ip address on firewall ( 172.172.172.1 ) ?
what if i have a secondary block on ISP 1 ( 172.172.173.x) ? how do i make it work ? it wasn’t working in drop in mode.
Yes. Ideally WAN1 IP block should be equivalent or greater than WAN2 IP block when you wish to do Drop-in.
This is depend. If you want to do 1 to 1 NAT, then you may use NAT Mapping in Peplink then NAT to Firewall IP block. If you want to do Port Forwarding, then you may NAT WAN2 interface IP on Peplink to Firewall interface with specific port.
This is working when you enable Drop-in mode. I assume your connection as below:-
ISP1 > Router > Peplink (Drop-in) > Firewall.
The network segment between router and firewall is 172.172.172.0/30 with floating IP 172.172.173.x which given by ISP1.
In this scenario, you may enable Drop-in with Shared IP (Network > LAN > Click ? in Drop-In Mode Settings) with setting below:-
Management IP Address: <Configure 1 of the floating IP>