StarTrek4U
Gawd
- Joined
- Jan 8, 2003
- Messages
- 1,011
So my understanding is this should be possible, but maybe I'm wrong....
I have two separate public IP ranges from my ISP. The second one was just added. What I'm trying to do is get both address ranges forwarded to the single external interface on my firewall. which will then be setup to do the NAT, etc for both ranges. Here's my setup (IP addresses are for illustration only):
First Public Range: 10.10.31.48 /28
Second Public Range: 10.10.31.160 /27
The devices are setup like this:
Internet --> ISP Router --> External Switch --> Firewalls --> Internal Network
The external switch is there to do some vlans for other external devices we have.
The initial public IP range is setup on VLAN 11 and everything works great. My ISP is sending both subnets to our switch. I added a secondary IP address to VLAN 11 to accept traffic from the second range. My firewall limits me to one IP on an external interface but will do additional NAT, so I setup a static route to forward the second public IP range to the external interface on my firewall (which has an address on the first IP range).
My problem is I can't get the switch to pass traffic from the second public IP range to the firewall. I can get as far as pinging the secondary IP address of the switch from an external source but when I try to ping a different address on that subnet that the firewall is supposed to NAT for, it doesn't go any farther.
Any ideas? Or does this make no sense at all...
I have two separate public IP ranges from my ISP. The second one was just added. What I'm trying to do is get both address ranges forwarded to the single external interface on my firewall. which will then be setup to do the NAT, etc for both ranges. Here's my setup (IP addresses are for illustration only):
First Public Range: 10.10.31.48 /28
Second Public Range: 10.10.31.160 /27
The devices are setup like this:
Internet --> ISP Router --> External Switch --> Firewalls --> Internal Network
The external switch is there to do some vlans for other external devices we have.
The initial public IP range is setup on VLAN 11 and everything works great. My ISP is sending both subnets to our switch. I added a secondary IP address to VLAN 11 to accept traffic from the second range. My firewall limits me to one IP on an external interface but will do additional NAT, so I setup a static route to forward the second public IP range to the external interface on my firewall (which has an address on the first IP range).
My problem is I can't get the switch to pass traffic from the second public IP range to the firewall. I can get as far as pinging the secondary IP address of the switch from an external source but when I try to ping a different address on that subnet that the firewall is supposed to NAT for, it doesn't go any farther.
Any ideas? Or does this make no sense at all...