Solved

Router configuration for multiple ISP assigned IP addresses

Posted on 2014-11-11
11
313 Views
Last Modified: 2014-11-22
Hi,

We have block of five IP addresses assigned to us from our ISP. They were routed through an ADSL connection to a Zyxel P-660 router, and we used three of them directly on the second NICs of three servers. The Zyxel quite happily allowed all ports to be directly accessed on these three servers from outside.

Unfortunately this router has died and is "end of line", and we have now been provided with a Linksys X3500 as an alternative by our ISP. I have disabled NAT and turned off the firewall. The servers can all access the internet outbound but no inbound connections are being received from outside.

Anyone got any ideas what the problem might be?

Thanks,

Jim.
0
Comment
Question by:e-matters
  • 5
  • 3
  • 2
  • +1
11 Comments
 
LVL 3

Expert Comment

by:Matt D
ID: 40435920
Are you only using the Linksys X3500 as both the modem and router, or do you have other devices between the Linksys X3500 and your switches / servers?

How do you have the DMZ settings configured?
0
 

Author Comment

by:e-matters
ID: 40435978
Hi Matt,

Linksys is both modem and router. There is nothing between the servers and the Linksys. The servers have two NICs - one has one of the ISPs assigned IPs, the other has a 10.0.97.x IP address.

All worked great with the Zyxel.

Jim.
0
 
LVL 3

Expert Comment

by:mrodriques
ID: 40436151
So am I understanding correctly when you say that the ADSL is connecting directly into the Linksys device?  

I'm thinking that you need a router that will allow you to NAT those routable IP's across your network to the server you're trying to allow them to access.

If the device you have can NAT out the routable to non-routable address, than great.  If not, I'd look at http://www.bhphotovideo.com/bnh/controller/home?O=&sku=827006&gclid=CjwKEAiAhIejBRCKm_fTxIWyyXcSJABXY0XYkfewqsZ4pMYhTiSMzhRER-mJLUxaF486y7ks6r2gPhoC4cDw_wcB&Q=&is=REG&A=details or something comparable.

Good Luck
0
 
LVL 45

Expert Comment

by:Craig Beck
ID: 40436164
If I'm understanding this you were using IP Alias on the Zyxel box?  IIRC you can assign multiple IP ranges to the LAN so you will have had your block of 5 addresses routed via the WAN port.  With the Linksys box I think you'd be stuck to using the block on the WAN port and being forced to use NAT.

The way that some ISPs provide blocks of IPs on DSL circuits is a bit funny.  For example some providers will dynamically assign the block to your router via PPP but others will route to it via a dynamic IP assigned to your router when it establishes a PPP connection.  If you have the latter you're fine, but it sounds like you don't.
0
 

Author Comment

by:e-matters
ID: 40436292
Hi, thanks for the comments.

I have bought a replacement Zyxel but it will take a couple of days to get here.

The Linksys has the option to Disable NAT which is allowing all of the servers to get outbound connections. What I don't get is why I cannot access any of the ports coming in the way. If I can get out, then if the Linksys gets a packet for one of the ISP IPs on the inside of the network then why doesn't it go "there you go" and pass it over, regardless of port? As I can connect from the internal servers to the outside world through the Linksys then packets are definitely going back and forth successfully.
0
Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

 
LVL 45

Expert Comment

by:Craig Beck
ID: 40436343
Ah...

That just sounds like you have a SPI firewall enabled on the router then.  If you have just disable it and try again.
0
 

Author Comment

by:e-matters
ID: 40436732
Hi, SPI firewall is an option, but already disabled.
0
 
LVL 3

Expert Comment

by:Matt D
ID: 40436735
I would contact Linksys for support on this issue, if that's possible for you.
0
 

Accepted Solution

by:
e-matters earned 0 total points
ID: 40446764
Hi,

Thanks for the comments. I've contacted Linksys but don't hold out much hope. We have the replacement Zyxel box now, and it is working away fine.
0
 

Author Closing Comment

by:e-matters
ID: 40459211
Unfortunately we couldn't get the Linksys router to work for us, but the replacement Zyxel has arrived, which we know will work.
0
 
LVL 45

Expert Comment

by:Craig Beck
ID: 40459282
0

Featured Post

Top 6 Sources for Identifying Threat Actor TTPs

Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

Join & Write a Comment

This solves the problem of diagnosing why an internet connection is no longer working. It also helps identify the likely cause of the lost connection if the procedure fails to re-establish your internet connection. It helps to pinpoint the likely co…
Hello , This is a short article on how would you go about enabling traceoptions on a Juniper router . Traceoptions are similar to Cisco debug commands but these traceoptions are implemented in Juniper networks router . The following demonstr…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now