Results 1 to 3 of 3

Thread: VLANs and NAT

  1. #1
    Newbie
    Join Date
    Nov 2010
    Posts
    2

    Question VLANs and NAT

    I did a search but was unable to come up with a concrete solution.

    I have two VLANs of which one contains my Untangle box. I am unable to get past the untangle box from the other VLAN.

    I believe this is a NAT issue but I am not certain.

    Background:
    Network topology is attached.

    My Untangle box does our NAT Routing and has a public address on the external interface.
    The internal interface has the ip address 192.168.200.253(/24).

    My L3 Switch (Nortel ERS 4500) has a routing interface with IP address 192.168.200.254 on VLAN 200 and 192.168.202.1 on VLAN 202.

    All of my network devices look to the ERS as their first hop router (default gateway). The ERS has a default route built pointing to Untangle (192.168.200.253).

    All traffic to Untangle is untagged and on VLAN 200.

    Untangle has a route built to access 192.168.202.0/24 through 192.168.200.254.

    Untangle's first hop/default gateway is my WAN Router (208.X.35.153).

    Behavior:

    All traffic on VLAN 200 works like a champion.

    From VLAN 202, I can ping Untangle's internal interface (192.168.200.253) and external interface (208.X.35.154).

    I cannot ping the WAN router (208.X.35.153) from VLAN 202.

    My thoughts:

    I know from my research that Untangle does not handle VLANs. All traffic to Untangle is untagged. From VLAN 202, I can talk to Untangle directly (responds to ping, http, etc.) but I cannot get 'beyond' Untangle. I believe I am missing something with my NAT settings on Untangle but it could also be that what I am doing is impossible. While I'm fairly decent with IP and static routing, NAT is far from my specialty.

    I would really appreciate any help.
    Attached Images Attached Images
    Last edited by Hyper-W; 11-10-2010 at 12:15 PM. Reason: clarification

  2. #2
    Untangle Junkie dmorris's Avatar
    Join Date
    Nov 2006
    Location
    San Mateo, CA
    Posts
    11,691

    Default

    I would try changing the netmask to /16 on the untangle internal interface.
    /24 does not contain all of your networks.

    If that does not work I would add an alias on the internal interface of 192.168.202.2/24

    welcome to the forums!
    Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself.
    If you need Untangle support please call or email support@untangle.com

  3. #3
    Newbie
    Join Date
    Nov 2010
    Posts
    2

    Default

    Quote Originally Posted by dmorris View Post
    I would try changing the netmask to /16 on the untangle internal interface.
    /24 does not contain all of your networks.

    If that does not work I would add an alias on the internal interface of 192.168.202.2/24

    welcome to the forums!
    Thanks, I'll give that a shot after-hours and post back with an update.

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

SEO by vBSEO 3.6.0 PL2