WG: Would like to route Secondary IPs on LAN | Zwei Secondary IPs neben dem Hauptnetz

<[email protected]> Fri, 11 Apr 2014 13:13:28 +0000
Newsgroups gmane.comp.security.firewalls.m0n0wall
Message-ID <C7B315DBEEC8CA40B5A53DDC29704EEF19D4F0FD@exmbx1.exchange.ruhr-uni-bochum.de>

Dear Joschka.



Now it is :





http://s7.directupload.net/images/140411/ti5jz69x.jpg



But it ist he same : Ill get now answere from the pinged client



Best wishes



Dennis







-----Ursprüngliche Nachricht-----
Von: Joschka Blohm [mailto:[email protected]]
Gesendet: Freitag, 11. April 2014 14:58
An: [email protected]<mailto:[email protected]>
Betreff: Re: [m0n0wall] Would like to route Secondary IPs on LAN | Zwei Secondary IPs neben dem Hauptnetz



Dear Dennis,



have a firm look on your destination and source networks.

As far as what you have said you have set the route to 10.147.211.0/24 correctly, but you have to define this rule the other way round, so that the clients from 10.147.211.0/24 can access your LAN network.



      +---------+---------------+------+----------------+------+

      |  Proto  | Source        | Port | Destination    | Port |

      |---------|---------------|------|----------------|------|

      |    *    |    LAN net    |  *   |10.147.211.0/24 |   *  |

      |         |               |      |                |      |

--->  |    *    |10.147.211.0/24|  *   |     LAN net    |   *  |

      +---------+---------------+------+----------------+------+



HTH



Regards,



Joschka



Am 11.04.2014 14:04, schrieb [email protected]<mailto:[email protected]>:

> Dear Joscka.

>

> What i have done :

>

> On my LAN Interface i insert the secondary Network 10.147.211.0/24 In

> den LAN Rules I set an any->any rule to this network ( or have I set it in the wan section ?

>

> Best wishes

>

> Dennis

>

>

>

>

>

> -----Ursprüngliche Nachricht-----

> Von: Joschka Blohm [mailto:[email protected]]

> Gesendet: Freitag, 11. April 2014 13:27

> An: [email protected]<mailto:[email protected]>

> Betreff: Re: [m0n0wall] Would like to route Secondary IPs on LAN |

> Zwei Secondary IPs neben dem Hauptnetz

>

> Dear Dennis,

>

> have you set the right firewall rules to allow the traffic from the XP network to the normal network?

>

> As default there is only one rule to allow routing from the LAN net to any other network.

>

> Maybe you may wish to clarify what you have done so far (e.g. firewall rules).

>

> Unfortunately I do not have a working setup with secondary IPs for testing.

>

> Regards

>

> Joschka

>

> Am 11.04.2014 10:35, schrieb [email protected]<mailto:[email protected]>:

>> Dear all.

>>

>> I would like to route 1 IP Range (10.147.211.0/24 ) next to my normal network. So i put it into the Secondary IPs of my LAN interface. But if i would like to connect from this (10.147.211.0/24 ) to my normal network i get now connection. The connection from my normal network to the (10.147.211.0/24 )  is okay. I can ping anything and use remote connections for example.

>>

>> Any help ?

>>

>> Best wishes

>>

>> ----------------------------------------------------------------

>>

>>

>> Hallo zusammen.

>>

>> Da einige Rechner bei uns nicht von Windows XP-> Windows 7 umgestellt werden können habe ich diese in ein seperates Netz ohne Verbindung nach außen gepackt. Diese können nach der Einrichtung aus dem normalen Netz erreicht werden.

>>

>> Leider können diese aber nicht aus dem seperaten Netz in das normale Netz pingen oder sonst etwas. ich habe diese unter Secondary IPs eingetragen aber bekomme noch immer keine Verbindung.

>>

>> Kann mir jemand helfen ?

>>

>> LG

>>

>>

>>

>

> ---------------------------------------------------------------------

> To unsubscribe, e-mail: [email protected]<mailto:[email protected]>

> For additional commands, e-mail: [email protected]<mailto:[email protected]>

>

>

> ---------------------------------------------------------------------

> To unsubscribe, e-mail: [email protected]<mailto:[email protected]>

> For additional commands, e-mail: [email protected]<mailto:[email protected]>

>



--

Diese E-Mail und eventuelle Anlagen können vertrauliche und/oder rechtlich geschützte Informationen enthalten. Wenn Sie nicht der richtige Adressat sind oder diese E-Mail irrtümlich erhalten haben, informieren Sie bitte sofort den Absender und vernichten Sie diese E-Mail. Das unerlaubte Kopieren sowie die unbefugte Weitergabe dieser E-Mail sind nicht gestattet.



This e-mail and any attachments may contain confidential and/or privileged information. If you are not the intended recipient (or have received this e-mail in error) please notify the sender immediately and destroy this e-mail. Any unauthorized copying, disclosure or distribution of the material in this e-mail is strictly forbidden.



---------------------------------------------------------------------

To unsubscribe, e-mail: [email protected]<mailto:[email protected]>

For additional commands, e-mail: [email protected]<mailto:[email protected]>