This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Assistance to setup multiple WAN on different network

Dear all,

 

This is the wan info i got from my ISP

x.x.134.214 (main)
x.x.73.248 - x.x.73.250 / 29

 

Currently, I have 3 VLAN 10,20,30.

 

May i know how can i assign

 

- x.x.73.249 to VLAN 10 (192.168.1.x)

- x.x.73.250 to VLAN 20 (172.168.1.x) 

 

Thank you very much for your time.

 

Warm regards,

Peter



This thread was automatically locked due to age.
  • First you have to unable Uplink Balancing, it can be enabled by itself when you check in both wan "Default Gateway".

    In Interface > Multipath Rules, create a rule on top with persistence "By Interface"

    Do the proper masquerading in NAT too. And thats it

  • Dear Oldeda,

     

    Please excuse me, as i am new. Can you give me a bit more help.

     

    Interface -> Multipath Rules

    Source : (VLAN Network) 192.168.1.0/24
    Destination : (WAN 249) x.x.73.249/29
    ltf.Persistance: By Interface
    Bind Interface : WAN (x.x.34.214)


    and finally you also mentioned NAT.
    Should I use 1:1 NAT (whole networks)

    traffic from :(WAN 249) x.x.73.249/29
    going to :(VLAN Network) 192.168.1.0/24

    1:1 NAT Mode : Please advise Map Source / Destination
    Map to : Please advise

     

     

    Thank you very much for your kind response.

    Warm regards,

    Peter

  • First question:

    Destination any

    Second Question: Under NAT>Masquerading TAB, not NAT rule. You should have only one rule there already

  • Thanks Oldeda!

    It's working!

    1. additional (Static 249) address x.x.73.249 for WAN under Interfaces & Routing -> Additional Address.

    2. network 172.168.x.x (network) -> WAN , use address (Static 249)

    3. disable uplink balancing

     

    LOL we solved one problem but another arise.

    If i need to maintain my WAN2 to fail over how can I do so ?

     

    Warm regards,

    Peter Lai

  • Uplink Balancing will do that. I know tha way you mentioned, but multipath rule is the easy way.

    Without Uplink Balancing, the system (UTM) will not known that you have two WAN.

  • Also, make sure your Masq rules for the subnets all use "Uplink Interfaces" instead of "WAN1" or 2.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA