Solved

1 WAN to 2 LAN

Posted on 2016-09-25
4
69 Views
Last Modified: 2016-09-27
Hi all

Im working on a school. For now we used 2 routers with its own WAN to seperate student and admin network.

I want to get rid of 1 router, to use the new advanced router for both networks.

Its a Zyxel Zywall 310.

I managed to make 1 WAN, and 2 LAN (see image)
1 WAN to 2 LAN
It works fine because i got seperate switches and cables for each network. So its not a vlan and i guees its not important to create a vlan?
Thats what im asking for.
Is this setup valid? Can the 2 networks connect to each other? They may not be able to.
I know they can ping eachother, but a part from that, the networks most be completely seperated. Are they?

Is there anything to take into consideration, before deploying this pretty simple setup?

Best regards
Mike Kristensen
IT admin
0
Comment
Question by:Mike Kristensen
  • 2
  • 2
4 Comments
 
LVL 69

Accepted Solution

by:
Qlemo earned 500 total points
ID: 41814699
I can only base advice on the User Manual.
ge3 is configured as LAN, ge4 as DMZ by default. Did you change the zone for latter?

To be able to use firewall policies to the full extent, you'll need to put the LAN interfaces into different zones, as policies are applied whenever traffic crosses zones (not interfaces). For intra-zone traffic you can only set up allow-all or deny-all (not sure about that, the manual is ambiguous at page 209).
I recommend to use two zones like "Students" and "Admin", and put each interface into one of them, then set up policies to define which kind of traffic may be passing. You can set up different rules for the admin network to have full access to the students', while blocking anything but ICMP coming from students network.
0
 

Author Comment

by:Mike Kristensen
ID: 41814713
Okay cool. I will try to fix that. For now they are in zone "LAN". But both in that zone. Whenever i pick LAN1 or LAN2 zone, the WAN connection seems to not be connected to LAN1 or LAN2.

Are zones just something you configure? Or does it actually does something specific? Or can you create your own zone, with your own rules? And that is kinda how zones work?

For me it seems like zones are doing something to the ports. But i dont have to use them. I can use port 1 as WAN if i like, and port 2 as LAN etc. etc .?

Is this true?Unavngivet.jpg
0
 
LVL 69

Expert Comment

by:Qlemo
ID: 41814830
You can create and names zones as you like. New zones require new firewall rules, though.
Interfaces have a default zone, but you can change that. Interfaces can be member of exactly one zone.
0
 

Author Closing Comment

by:Mike Kristensen
ID: 41819207
I did what you said and its working fine.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
How to restrict all websites and allow only citrix website 5 44
Wired Network vs Wireless 12 53
HP Procurve and AAA authentication 2 25
VLAN Question! 9 42
In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
If you're not part of the solution, you're part of the problem.   Tips on how to secure IoT devices, even the dumbest ones, so they can't be used as part of a DDoS botnet.  Use PRTG Network Monitor as one of the building blocks, to detect unusual…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

815 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now