Router Config Draytek 2820 - External IP address

Posted on 2010-11-16
Last Modified: 2012-05-10
Hi all, I've got a Draytek 2820 with an ADSL2+ line with a static IP Address.
All works fine and well.

However, what I'd like to do is

1. Get another external IP address, namely IP address A and IP address B
2. Configure one internal machine to have the external IP address A. Meaning that in the network settings of the windows 2008 server (which I intend to make it), it will be an external IP and not an internal IP and NAT-ed by the router.
3. The local LAN (not including the external faced machine mentioned in no.2) will be NAT-ed for internet access.

Can you advise if I'm on the right track as per the diagram I cooked up. As well as what Draytek model or what generic advice you can provide.

Thanks a million!

 Proposed Network Diagram
Question by:binele
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions

Expert Comment

by:Steve Moss
ID: 34154046
The 2820 has a multi-NAT feature which you can use, as explained here: Using MultiNAT.

But I have to ask - why you are trying to do this?? SBS 2008 has very good remote access facilities, and none of these require multiple public IP addresses. Also, the way you have illustrated your intended setup, you have the LAN workstations on a separate subnet from the SBS 2008 (which won't work), connected via a second router.

Expert Comment

ID: 34156596
Yes a good way would be to follow the above guide. I also agree with cocospm. You would be far better using port forward on the services you require to have public access on the 2008 server.

If its becuse you want to isolate the server totally you would be better having the draytek 3300V+ as this has true DMZ

If you wanted to do this you would need a simple adsl modem ( you could use your current router - set it up using the second lan range, just put in your public address) to sit in front of the 3300v.
SEtup the 2008 server in the dmz and your regualr clients behind the lan ports of the 3300v.

Author Comment

ID: 34157405
Hi, we intend to install 3cx SIP server on the windows 2008 server. Even though it works behind a firewall with port forwarding etc, there is still an issue with remote hard phones (outside the current network). To avoid any problems with firewalls issues, compatibility and all, we've tested with an internet based server as a test. Now the challenge is to get the current infrastructure we've got (which is an internal server) to act as an internet facing server directly.

The multiNAT feature will not work in what I'm trying to achieve as it still is "PORT FORWARDING" to the designated server.

I understand from Draytek support that you can use the IP ROUTING Feature under the LAN settings. Not sure if this will work as I haven't tried it yet... I didn't think they understood my requirements though....

Any thoughts?

Accepted Solution

q2q earned 450 total points
ID: 34162211
yes I have used the IP routing feature before, it works by setting up a second ip range in the lan setting (it is labeled as routing purposes). I normally put the newly allocated ip range in the range complete with subnet. Then anything attached to the router configured with a public wan ip from the 2nd range works as if directly hooked up.
IF you want to do it this wasy you are limited to one ip range (doesnt matter how big) so it may be worth getting a reasnable range in case you ever want to expand.
So to clarify as an example

fixed ip WAN of adsl would be (WAN > Internet access > WAN1 ) unchanged
your current public ip range
In the IP alias section ass the 1st public address from your allocated range eg
your lan setttings (LAN > GENERAL SETUP, 1st IP addrss) would be unchanged
your lan setttings (LAN > GENERAL SETUP, 2nd IP address) would be set to
ip address -
set RIP to protocol control to 2nd subnet

This is an example of a small block of 8
You would then setup the network card on you 2008 server to use with the same subnet and a gateway of (the alias ip given to the router)

Hope this makes sense.


Assisted Solution

Ravenbridge earned 50 total points
ID: 34172277

Further to q2q's excelent explanation, I can confirm that the solution will work, but you must also ensure that you haven't added the public ip addresses to the NAT pool.

Go to Wan - Internet Access - Wan1 - PPPoA / PPPoE click on WAN IP Alias and make sure that your block of public IP addresses are not listed

Featured Post

Why Off-Site Backups Are The Only Way To Go

You are probably backing up your data—but how and where? Ransomware is on the rise and there are variants that specifically target backups. Read on to discover why off-site is the way to go.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you're not part of the solution, you're part of the problem.   Tips on how to secure IoT devices, even the dumbest ones, so they can't be used as part of a DDoS botnet.  Use PRTG Network Monitor as one of the building blocks, to detect unusual…
When it comes to security, there are always trade-offs between security and convenience/ease of administration. This article examines some of the main pros and cons of using key authentication vs password authentication for hosting an SFTP server.
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…
In this brief tutorial Pawel from AdRem Software explains how you can quickly find out which services are running on your network, or what are the IP addresses of servers responsible for each service. Software used is freeware NetCrunch Tools (https…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question