Hello Everyone!
Hopefully this is a straightforward question and someone has a solution. On the Peplink Balance 20X I’m testing/deploying I can’t access the management network (web portal) I’ve created from a different subnet, I have to use the tagged vlan on the same subnet to access the device, not a big deal in practice but I was wondering if that was by design or if a setting may have been missed somewhere.
Both Subnets are part of the same /16
Management IP range example X.X.A.X/24
Other Tagged subnet example X.X.B.X/24
We’ve attached the Peplink to the core L3 switch, trunked the connection, and have access to the internet when we cut the line from the main ISP, that works fine. The weirdness occurs when trying to log into the peplink for administration.
Peplink management (untagged vlan) is in the same Subnet as the switches X.X.A.X
Other peplink Interface (tagged vlan) is in a different subnet X.X.B.X
From the peplink management interface X.X.A.X IP I can ping My test Machine in the X.X.B.X subnet and can confirm both from the peplink and wireshark ping packets make the full trip perfectly. The problem is I can’t do the same in reverse. Which is why I’m thinking something in the peplink itself is blocking this/needs to be changed. Looking at the packets from the machine back to the peplink, the pings get to the peplink and are then dropped.
Again this is not a super big deal, just wondering if anyone knows what exactly this could be caused by.
TLDR: Subnet A to Subnet A interface works, Subnet B to Subnet B interface works. Peplink in A to Machine in B works, but not when the machine initiates. The incoming connection seems to be getting blocked/dropped/denied. Inter-Vlan Routing is on for the tagged subnet on the peplink, and when traceroute is ran both connections take the path to the core L3 switch. Everything looks fine, but the peplink seems to be actively denying the request unless it is on the same subnet. This is the only device on the network that does this, routing between these two subnets is working correctly everywhere else, again leading me to something on the peplink. If more info is required, if this is too vague, or if someone has any suggestions please let me know.
I’ve tried static routes on the peplink, firewall rules on the peplink (including an any any), and factory resetting to make sure some other setting wasn’t clicked before this project came over to me. I appreciate any and all suggestions.