Solved

Port Forwarding from modem/router to another router

Posted on 2006-06-18
6
417 Views
Last Modified: 2010-05-18
Hi,

I am in a situation where I have 2 routers installated for my network. The first router is also a modem and was issued by the ISP and is locked on the LAN side to the 10.X.X.X address range. The second device is a router/wireless/firewall which its LAN portion addess has been set to the 192.168.0.X network range.  The first router/modem is connect via cat5 from its LAN port to the second routers WAN port and internet is coming through fine to the 192.168.0.x network. The problem I am having is enabling remote access (RDP 3389) to forward through from the first router, to the second and onto the desired workstation (192.168.0.3).

Currently in both routers I have enabled port forwarding for TCP port 3389 to forward to the 192.168.0.3 workstation. When I test this connection from a client outside on the internet it does not make a connection. Can anyone please tell me if I am doing something wrong in this scenario?

Thanks.

0
Comment
Question by:amerretz
  • 3
  • 3
6 Comments
 
LVL 13

Expert Comment

by:td_miles
Comment Utility
On the ISP supplied router, you will need to forward port 3389 to the WAN port IP address of your second router (this will be a 10.x.x.x address) and then on the second router forward the port to your internal machine.
0
 

Author Comment

by:amerretz
Comment Utility
So let me get this straight.  If the ISP's router address is 10.0.0.138 then how can I find out the address that is being issued to the WAN port of the second router in the 10.x.x.x  newtwork. Wouldnt the second router have 2 addresses assigned to the WAN port, one side for the 10.x.x.x network and the other for the 192.168.0.x network? Is this right?

Thanks
0
 
LVL 13

Expert Comment

by:td_miles
Comment Utility
bigpond ?

The second router should have some admin interface that will tell you what it's WAN address is. It will have gotten one from your ISP router using DHCP. It's WAN address will be 10.0.0.x and it's LAN address will be 192.168.0.x.

The most basic fundamental theory of routers says that it's interfaces need to have IP address on different subnets for it to work.
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 

Author Comment

by:amerretz
Comment Utility
Yeah bigpond, speedtouch modem. Ok so I will check through the second routers status pages. Then will forward 3389 to this address in the first router, then forward from the second router to the LAN client.

In this case will I need to create two port forwarding rules in the first router. The first rule forwarding 3389 from any host (internet 0.0.0.0) to 10.0.0.138 then another forward rule from 10.0.0.138 to 10.0.0.x (once I find the issued address on the second router). And, just a single rule on the second router of 10.0.0.x to 192.168.0.x. I maybe wrong in asking this but my other thought is maybe the double forward is not necessary because the router will handle the translation.

Thanks.

0
 
LVL 13

Accepted Solution

by:
td_miles earned 500 total points
Comment Utility
No, you don't need to initially forward to the IP address of your Speedtouch router (10.0.0.138).

On the speedtouch, forward port 3389 to the IP address that you find out is the WAN IP address on your second router. On the second router forward port 3389 to your internal IP address. Thus traffic will flow as follows:

Internet user connects to WAN IP address of speedtouch router (dynamically supplied by ISP on connect).
Speedtouch router maps/forwards the packet to 10.0.0.x (WAN IP of 2nd ruoter)
Second router receives the packet on its WAN IP 10.0.0.x
Second router translates/forwards the packet to 192.168.0.3
Host 192.168.0.3 receives packet from the Internet after it has been translated/forwarded by both devices.

Are you sure the speedtouch is locked ? Have you tried the default admin passwords for it (google search will find them for you) ? If you have your own router, you could put the speedtouch into bridged mode and just use your own router (if it doesn't have ADSL modem built in), this would make things easier.
0
 

Author Comment

by:amerretz
Comment Utility
Ok I understand now.

1st Ext--- x.x.x.x Dynamic ISP
|
1st Int --- 10.0.0.138 Static
|                                          <  Forward to 10.0.0.x
2nd Ext --- 10.0.0.x Static
|
2nd Int --- 192.168.0.1
|                                       < Forward to 192.168.0.3
Client --- 192.168.0.3
          GW 192.168.0.1
          DNS 192.168.0.1


I tried to change the LAN Ip on the speedtouch and I couldnt figure out how, I could only add an additional LAN IP.  The second router doesnt have a modem built in.


Thanks for all your help, really appreciate it!

0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Show ip route - definition 1 59
Routing VLANs 5 44
Static route between two Sonicwalls 6 33
Failover VDSL Modems 3 20
Hello , This is a short article on how would you go about enabling traceoptions on a Juniper router . Traceoptions are similar to Cisco debug commands but these traceoptions are implemented in Juniper networks router . The following demonstr…
Creating an OSPF network that automatically (dynamically) reroutes network traffic over other connections to prevent network downtime.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now