Solved

Watchguard XTM routing

Posted on 2013-11-19
6
671 Views
Last Modified: 2013-11-25
Hey

I have a Watchguard XTM33 firewall :)

I have 1 internet connection in port 0 (DHCP)
I have 1 IPTV connection in port 1 (DHCP)

All internet traffic to port 0 (internet)
Traffic to network 240.10.0.0/24 have to go to port 1.

How do I create a route? (using webgui)

Thanks in advance.

Mike
0
Comment
Question by:mikeydk
  • 3
  • 3
6 Comments
 
LVL 3

Expert Comment

by:RKnebel512
ID: 39663806
What route do you need to create?

The watchguard should be smart enough to send anything that is heading to the 240.10.0.0/24 subnet out port 1, and anything else should be sent out port 0 towards the default gateway.

But if needed, additional can be created by going through the Watchguard Policy Manager.  On the network menu, select Routes.
0
 

Author Comment

by:mikeydk
ID: 39665748
Port 0 IP 92.92.0.1
Port 1 IP 10.20.1.1 and behind this is 240.10.0.0 net
0
 
LVL 3

Expert Comment

by:RKnebel512
ID: 39666266
Okay.  At the main screen of the Web UI, after you log in, choose the "network" menu from the top of the window, then select "routes".

Click "Add"

in the Choose Type dropdown, choose "Network IPv4"

in the route To box, type in "240.10.0.0/24"

In the Gateway box, type in 10.20.1.1

click "OK"

Make sure you save the configuration afterwards.
0
Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

 

Author Comment

by:mikeydk
ID: 39666473
I get the following error When adding route. "Network IP is not valid because its first octet is over 233 * Ip addresses with octet over 233 arme reserved address spaces."
0
 

Author Comment

by:mikeydk
ID: 39666477
Sorry over 223 ;)
0
 
LVL 3

Accepted Solution

by:
RKnebel512 earned 500 total points
ID: 39666562
Oh yeah.  Anything 240 and above is considered a class E internet address and is reserved for "experimental" use.  They aren't considered publicly routable and many routers block them as a general rule.  I'm not sure you'll be able to get the watchguard to route that.

RFC 6890 lists IP subnets that are reserved for various reasons.

http://tools.ietf.org/html/rfc6890

I'm not sure if it's an option, but you might consider changing the address of that subnet to one that is recognized as routable.
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Hi there, This article summarizes what you need if you are going to set up your home or small business Network Attached Storage (NAS) to be accessible from the internet. Of course there are configuration differences based on your NAS or router ma…
Getting hacked is no longer a matter or "if you get hacked" — the 2016 cyber threat landscape is now titled "when you get hacked." When it happens — will you be proactive, or reactive?
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now