How to configure a connected Peplink device on DMZ/no-NAT


We’ve recently bought a Peplink 310 balancer for our office connection and it works incredibly good, but I’m having some minor thoughts about how I should go about and configure this setup properly.

Currently, our setup looks like this:

WAN1 . . WAN2
. | . . . . . .| .
Static . . . DHCP (both from ISP’s obviously)
. | . . . . . .| .

. . . .
NATed address from Peplink DHCPD (
. . . .

. . . .
NATed address from Mikrotik DHCPD (10.0.x.x/24)
. . . .
A number of client endpoints

As you can see, this gives me a Double-NAT situation where I find it very frustrating to do as simple stuff as port forwarding and alike so what I’m trying to find is a solution to put the Mikrotik router in some sort of DMZ or a non-NAT sort of setup, so the Mikrotik can get an IP-address directly from the ISP and not a nat’ed address from the Peplink.
I know you’re going to reply “But what about when it fails over to the static WAN?”, and this can be easily sorted in the Mikrotik, so you don’t have to think about that.

Any thoughts about this?
All kind of response is greatly appriciated.

(I’m sorry for the poor ASCII)

Best Regards
Lars Engström

How many static IP we have on WAN1? It sounds like we might be able to take advantage of Drop-in mode to eliminate double-NATing on WAN1.

More on Drop-in mode at Peplink | Pepwave - Forum

1 Like

Hello Kurt,

Last night I just realized that my post here basically would take the Peplink functionality away from the device, making it quite useless.

Anyway, yes, Drop-In mode actually do sound quite good because we have quite a few static IPs from our ISP, but what will happen when ISP1 fails and it fails over to ISP2?

Best Regards
Lars Engström

Yup if WAN1 fails, Peplink will failover to WAN2. Outbound traffic will use WAN2.

Please be reminded that the static IPs from WAN1 will be unreachable since now that WAN1 is down.

1 Like

Yeah this was my thought as well, if I put an IP-address from WAN1 statically on my Mikrotik router and it fails, it all goes down even though the Peplink uses WAN2 and have access, this kinda removes the failover functionality as well.
I guess it doesn’t have any settings that would allow me to set up two interfaces on the Mikrotik as WAN and then have the Peplink reroute the traffic to next interface if it fails over?

Dear Friend ,

Please be noted that while WAN1 is disconnected your clients and Mikrotik still have Internet connectivity by using WAN2. Just Static IP addresses routable through WAN1 is not accessible and the reason is clear.
fail over and load balancing works at this situation , you have outbound Internet access and your Inbound access would be possible through port forwarding and WAN2. when WAN1 connected your Inbound access would be taken by normally routing through WAN1.

1 Like

Hi Hootan, thanks for your reply.

So what you’re saying is that if i set a static external IP address from WAN1 (ISP1) on an interface on the Mikrotik and then WAN1 (ISP1) goes down, the outgoing traffic is still going through the Peplink but gets transferred through the WAN2 (ISP2) connection out to the internet?

Yes , this is correct. this is the beauty of the Drop-in mode . while you have static address range from your WAN1 and when WAN1 goes down. you still would have outbound Internet connectivity through WAN2.

1 Like

That’s very impressive, thank you very much.

I’ll try to set this up and if I run in to any problems I’ll give you a poke. :slight_smile:

Best Regards

You’re welcome. We have set up more than 50 Peplink routers like this :wink: be sure about that :slight_smile:

1 Like

I’ve now been trying to get this to work, but unfortunately my ISP only gives out “Dynamic static IPs”, in other words, my devices would use DHCP to get the IP, yet the IP is still bound to that MAC and made static from the ISPs point of view.
So … I’ve tried the Network Wizard to get this running, but since it tells me to input a static IP configuration I can’t really seem to solve it just yet.

Hi Lars,

The drop-in mode will not work for a dynamic IP address and you would need to subscribe to a /29 block of IP’s from your ISP.

We are currently working on perfecting drop-in mode without consuming any IP address, but this will be coming down the road - no ETA yet.

1 Like