03-27-2013 03:47 AM
is there anyone who can light up my day by posting a solution for NAT only for a specific ip address or a range of ip addresses from the same subnet?
i've read that the router in gateway mode automatically makes the translaltion and in router mode does not. Starting from this, is there any way to nat from firewall acces rules only
or if it is there another way to do it, please let me know.
thanks a lot.
03-27-2013 05:50 AM
With the gateway mode on RV082, a 1-to-1 NAT rule can make a range of private IP on the LAN side appear to be a range of public IP on the WAN side. RV082 supports up to ten 1-to-1 NAT rules.
03-27-2013 06:12 AM
thanks for your answer. i wasn't very explicit....i wil describe the situation for a better understanding.
one public ip set on wan1 interface
class c virtual ip's on lan interface ( 192.168.111.x ).
restrict http acces for all lan ip addresses on wan1 (nat or/and firewall ) and allow only certain ip addresses form same subnet (lan) to have acces to translation (or any other way to acces internet)
most of the ip's from lan pass through an ipsec tunnel to a proxy server located somewhere else and must not have acces directly to the internet. - this is working fine...
but there are some exceptions for some users.and those exceptions should have acces to the internet directly.
if the router is set in gateway mode, every ip from lan translates and have internet acces, even though there is a firewall rule about this: deny http wan1 any any .
is there a way i can solve this?
thanks a lot.
03-27-2013 06:30 AM
>if the router is set in gateway mode, every ip from lan translates and have internet acces, even though there is a firewall rule about this: deny http wan1 any any .
If you want to restrict internet access (http on port 80) for certain LAN IP range, the access rule should look like this:
deny http lan ip_range any
03-28-2013 04:23 AM
thanks for your answer, the rule works for all http traffic in lan. but this will restrict them also from accessing any http that's local. any local http server won't be accesable.
so i partially solved my problem with another firewall rule to allow http traffic through tunnel ip classes, allowing http acces through tunnel.
is there a way to allow local http open and restrict only the http internet traffic?
by that i mean to be able to acces http port on another lan computer.
i believe another firewall rule will solve this too
allow lan range ip destination ip (lan ip)
thanks a lot for your help.
03-28-2013 05:41 AM
>i believe another firewall rule will solve this too
Yes, you would need another allow rule, unless the local LAN IP and remote LAN IP that are allowed are part of the same class A subnet.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide