Dual WAN but second WAN only working inbound
Posted: Sun Feb 04, 2024 1:17 pm
I am having difficulties configuring a dual internet setup. I can successfully access the internet through isp1 but for the second isp it works for incomming connections to our webservers, sending out the web pages as expected but if the webservers try to go out themselves (for instance a ping), they fail.
Ether1 is Cerberus ISP, PPPoE connection (which works for connection initiated from internet only)
Ether2 is LAN 192.168.1.0/24 on ether-2 which can successfully browse the internet (via Brsk ISP on Ether5 as default)
Ether3 and Ether4 bridged as DMZ 192.168.0.0/24 (this is where the webservers are)
Ether5 is Brsk ISP, DHCP client connection (is default and works well)
If I have no rules then the DMZ goes out via Ether5 (default) and can browse the internet but I want DMZ to go out via Ether1 so have created mangle rules. Obviously I'm doing something wrong as with this rule in place the Webservers can successfully serve pages to the internet but if I try to do a ping from them to the internet it fails. It seems that if a connection is initiated from outside they work but if the connection is initiated inside they dont.
Config attached.
Ether1 is Cerberus ISP, PPPoE connection (which works for connection initiated from internet only)
Ether2 is LAN 192.168.1.0/24 on ether-2 which can successfully browse the internet (via Brsk ISP on Ether5 as default)
Ether3 and Ether4 bridged as DMZ 192.168.0.0/24 (this is where the webservers are)
Ether5 is Brsk ISP, DHCP client connection (is default and works well)
If I have no rules then the DMZ goes out via Ether5 (default) and can browse the internet but I want DMZ to go out via Ether1 so have created mangle rules. Obviously I'm doing something wrong as with this rule in place the Webservers can successfully serve pages to the internet but if I try to do a ping from them to the internet it fails. It seems that if a connection is initiated from outside they work but if the connection is initiated inside they dont.
Config attached.