Hello.
We have an edgerouter pro configured with a static WAN port. We have all the firewall rules in place for masqueradng, however clients on the LAN still cannot access the Internet. The router itself has Internet access.
Here is our config:
firewall { all-ping enable broadcast-ping disable ipv6-receive-redirects disable ipv6-src-route disable ip-src-route disable log-martians enable name WAN_IN { default-action drop enable-default-log rule 1 { action accept description "Allow established connections" state { established enable related enable } } rule 2 { action drop description "Drop invalid state" log enable state { invalid enable } } } name WAN_LOCAL { default-action drop enable-default-log rule 1 { action accept description "Allow established connections" state { established enable related enable } } rule 2 { action drop description "Drop invalid state" log enable state { invalid enable } } } receive-redirects disable send-redirects enable source-validation disable syn-cookies enable } interfaces { ethernet eth0 { address 68.65.X.X/28 duplex auto firewall { in { name WAN_IN } local { name WAN_LOCAL } } speed auto vif 1010 { address 100.64.0.1/31 description "NBRD Philly connection" mtu 1500 } vif 1011 { address 100.68.0.1/31 description "ACMA Connection" mtu 1500 } } ethernet eth1 { duplex auto speed auto } ethernet eth2 { duplex auto speed auto } ethernet eth3 { duplex auto speed auto } ethernet eth4 { duplex auto speed auto } ethernet eth5 { duplex auto speed auto } ethernet eth6 { duplex auto speed auto } ethernet eth7 { address 10.157.0.1/24 description MGMT duplex auto speed auto } loopback lo { } } service { dhcp-server { disabled false hostfile-update disable shared-network-name MGMT { authoritative disable subnet 10.157.0.0/24 { default-router 10.157.0.1 dns-server 8.8.8.8 dns-server 8.8.4.4 lease 86400 start 10.157.0.5 { stop 10.157.0.253 } } } use-dnsmasq disable } dns { } gui { http-port 80 https-port 443 listen-address 10.157.0.1 older-ciphers enable } nat { rule 5010 { description "Masquerade for WAN" outbound-interface eth0 type masquerade } } ssh { listen-address 10.157.0.1 port 22 protocol-version v2 } } system { host-name ubnt login { user ubnt { authentication { encrypted-password $1$zKNoUbAo$gomzUbYvgyUMcD436Wo66. } level admin } } name-server 8.8.8.8 name-server 8.8.4.4 ntp { server 0.ubnt.pool.ntp.org { } server 1.ubnt.pool.ntp.org { } server 2.ubnt.pool.ntp.org { } server 3.ubnt.pool.ntp.org { } } package { repository wheezy { components "main contrib non-free" distribution wheezy password "" url http://http.us.debian.org/debian username "" } } syslog { global { facility all { level notice } facility protocols { level debug } } } time-zone UTC } /* Warning: Do not remove the following line. */ /* === vyatta-config-version: "config-management@1:conntrack@1:cron@1:dhcp-relay@1:dhcp-server@4:firewall@5:ipsec@5:nat@3:qos@1:quagga@2:system@4:ubnt-pptp@1:ubnt-util@1:vrrp@1:webgui@1:webproxy@1:zone-policy@1" === */ /* Release version: v1.9.1.1.4977353.170426.0429 */
Any suggestions would be greatly appreciated. Thank you.