Double Nat / Router Cascade

Hello all,

I have been searching this forum for answers but I can’t seem to get my devices to work with what I have found.

I have a balance one core as my main router. It is on the 192.168.3.X network. I hooked a balance 20 to it (lan to wan) this router is on the 192.168.59.X network.

I have dhcp relay working on the balance 20 going to Microsoft Server 2012 DHCP. I put a static route on the core router in order to get it to work. (192.168.59.0 to 192.168.3.33) The 192.168.3.33 is the wan address of the balance 20.

On the core router I have two cable modems hooked into it. One has 2 static IPs and the other has five.

What I am trying to accomplish is being able to access devices on the balance 20 over the internet. Right now I have nat mapping on the core router, I selected one static from the first modem and two from the second going to the balance 20 wan (192.168.3.33)-- on the balance 20 I mapped the 192.168.3.33 to a PC running a website. (192.168.59.2)

Doesn’t work. I have tried to even send it to the balance 20 router admin page. I have set firewall rules and they don’t work.

Any ideas? All of the static IPs work when going to the balance core modem. Nothing seems to pass from the core to the 20. I also set the balance 20 to IP forwarding to turn off nat.

I really appreciate any help you can provide!
CJ

Forgot to add that both firmware is current.

Thanks again!
CJ

First thing to check is from a device on the 192.168.3.0 network can you view the website by accessing it using the WAN IP of the Balance 20 (http://192.168.3.33)

How are you testing the forwarding to the public IPs? The only way to do that from the LAN of either the Balance One Core or Balance 20 is to use a VPN so you don’t get NAT reflection / hairpinning.

1 Like

Hello,

I can access the site on the 192.168.3.0 network. That seems to be ok. For testing I have been using several different computers at different sites in different states using remote desktop as well as my cell phone with wifi turned off.

Thanks again for your help and time!
CJ

OK cool. So issue lies with the balance one core configuration. First question is what type of internet connection do you have? Is there another router on the WAN of the balance giving the balance one core a private IP address or is it getting a public IP?

Secondly - and I should have thought of this earlier, what happens if you do PAT on the balance core so redirect port 8080 on the WAN of the Balance Core to port 80 on 192.168.3.33? Have you disabled web admin on the WAN on the balance core (or moved it to a different port)?

1 Like

I have two cable modems and two 4G modems that I use. The 4G modems also have static IPs. They are setup as Backup Priority two.

All four modems go directly to the Balance Core and they all have static public IP addresses. Port forwarding and NAT works fine with devices using the Balance Core router.

I turned off web admin on the WAN for both routers while trying to troubleshoot. I tried PAT on the Balance Core using 8080 and 8089 going to port 80 on 192.168.3.33 and still no luck.

I have tried making firewall rules on the Balance Core with it being logged. Nothing shows up in the log except for the traffic going to the devices using the Balance Core. I think I have tried every combination of setups on both routers- turning NAT off on the Balance 20, NAT on the Core to the Balance 20 WAN then Balance 20 WAN to the device, Port Forwarding, firewall access. I turned one of the 4G modems over to always on and tried accessing through that with all of the above combinations. No luck either.

I also setup a spare Balance 20 on one of the cable modems. It has a public static IP on the WAN and I assigned it another additional static IP. I can view the web admin over the WAN with both static IPs. I turned off web admin for the wan after that. I cascaded this modem to the Balance 20 that we have been working on and it doesn’t work either. On the spare Balance 20 I forwarded all TCP and UDP ports over to the Balance 20 we have been working on (192.168.3.33). Nothing. On the spare Balance 20 I set the firewall to allow everything and log the events. In the event viewer I can see the proper source ip (my cell on the cell network) going to the destination (192.168.3.33). On the Balance 20 we have been working on I set the firewall the same with everything allowed and logged. I PAT 5556 to 80 going to the device with the web server and also turned on the web admin for the WAN. Nothing shows up in this event log and nothing happens like before. Everything times out.

I also setup a quick filezilla FTP server just to test and no go with it.

Any other ideas? This is driving me crazy but I am sure it is something simple that is throwing it all off.

Thanks again for your help and time!
CJ