Quantcast
Viewing all articles
Browse latest Browse all 20028

NAT Hairpin not working - New EdgeRouter

Hi,

 

Today I'm installing a new EdgeRouter.

- Internetconnection is with DHCP

- Default wizard WAN+LAN

- Configured L2TP VPN
- Configured port forwarding

 

NAT Hairpin is not working and is needed ASAP.

Can somebody help me? Thank you!

 

 firewall {
     all-ping enable
     broadcast-ping disable
     ipv6-receive-redirects disable
     ipv6-src-route disable
     ip-src-route disable
     log-martians enable
     name WAN_IN {
         default-action drop
         description "WAN to internal"
         rule 10 {
             action accept
             description "Allow established/related"
             state {
                 established enable
                 related enable
             }
         }
         rule 20 {
             action drop
             description "Drop invalid state"
             state {
                 invalid enable
             }
         }
     }
     name WAN_LOCAL {
         default-action drop
         description "WAN to router"
         rule 10 {
             action accept
             description "Allow established/related"
             state {
                 established enable
                 related enable
             }
         }
         rule 20 {
             action drop
             description "Drop invalid state"
             state {
                 invalid enable
             }
         }
         rule 21 {
             action accept
             description "Allow L2TP"
             destination {
                 port 500,1701,4500
             }
             log disable
             protocol udp
         }
         rule 22 {
             action accept
             description "Allow ESP"
             log disable
             protocol esp
         }
     }
     receive-redirects disable
     send-redirects enable
     source-validation disable
     syn-cookies enable
 }
 interfaces {
     bridge br0 {
         address 10.0.1.1/24
         aging 300
         bridged-conntrack disable
         description "Local Bridge"
         hello-time 2
         max-age 20
         priority 32768
         promiscuous enable
         stp false
     }
     ethernet eth0 {
         address dhcp
         description Internet
         duplex auto
         firewall {
             in {
                 name WAN_IN
             }
             local {
                 name WAN_LOCAL
             }
         }
         poe {
             output off
         }
         speed auto
     }
     ethernet eth1 {
         bridge-group {
             bridge br0
         }
         description "Local Bridge"
         duplex auto
         poe {
             output off
         }
         speed auto
     }
     ethernet eth2 {
         description "Local Bridge"
         duplex auto
         poe {
             output 24v
         }
         speed auto
     }
     ethernet eth3 {
         description "Local Bridge"
         duplex auto
         poe {
             output 24v
         }
         speed auto
     }
     ethernet eth4 {
         description "Local Bridge"
         duplex auto
         poe {
             output 24v
         }
         speed auto
     }
     loopback lo {
     }
     switch switch0 {
         bridge-group {
             bridge br0
         }
         description "Local Bridge"
         mtu 1500
         switch-port {
             interface eth2 {
             }
             interface eth3 {
             }
             interface eth4 {
             }
             vlan-aware disable
         }
     }
 }
 port-forward {
     auto-firewall enable
     hairpin-nat enable
     lan-interface eth1
     rule 1 {
         description "QNAP Filemanager"
         forward-to {
             address 10.0.1.253
             port 8080
         }
         original-port 8080
         protocol tcp_udp
     }
     rule 2 {
         description "QNAP Sabnzbd"
         forward-to {
             address 10.0.1.254
             port 8800
         }
         original-port 8800
         protocol tcp_udp
     }
     rule 3 {
         description "Camera 221"
         forward-to {
             address 10.0.1.221
             port 221
         }
         original-port 221
         protocol tcp_udp
     }
     rule 4 {
         description "Camera 222"
         forward-to {
             address 10.0.1.222
             port 222
         }
         original-port 222
         protocol tcp_udp
     }
     rule 5 {
         description "Camera 223"
         forward-to {
             address 10.0.1.223
             port 223
         }
         original-port 223
         protocol tcp_udp
     }
     wan-interface eth0
 }
 service {
     dhcp-server {
         disabled false
         hostfile-update disable
         shared-network-name LAN_BR {
             authoritative enable
             subnet 10.0.1.0/24 {
                 default-router 10.0.1.1
                 dns-server 10.0.1.1
                 lease 86400
                 start 10.0.1.38 {
                     stop 10.0.1.243
                 }
             }
         }
         use-dnsmasq disable
     }
     dns {
         dynamic {
             interface eth0 {
                 service dyndns {
                     host-name hostnamehere
                     login usernamehere
                     password passwordhere
                 }
                 web dyndns
             }
         }
         forwarding {
             cache-size 150
             listen-on br0
         }
     }
     gui {
         http-port 80
         https-port 443
         older-ciphers enable
     }
     nat {
         rule 5010 {
             description "masquerade for WAN"
             outbound-interface eth0
             type masquerade
         }
     }
     ssh {
         port 22
         protocol-version v2
     }
 }
 system {
     host-name ubnt
     login {
         user ubnt {
             authentication {
                 encrypted-password encryptedkeyhere
             }
             level admin
         }
     }
     ntp {
         server 0.ubnt.pool.ntp.org {
         }
         server 1.ubnt.pool.ntp.org {
         }
         server 2.ubnt.pool.ntp.org {
         }
         server 3.ubnt.pool.ntp.org {
         }
     }
     syslog {
         global {
             facility all {
                 level notice
             }
             facility protocols {
                 level debug
             }
         }
     }
     time-zone Europe/Amsterdam
     traffic-analysis {
         dpi enable
         export enable
     }
 }
 vpn {
     ipsec {
         auto-firewall-nat-exclude enable
         disable-uniqreqids
     }
     l2tp {
         remote-access {
             authentication {
                 local-users {
                     username usernamehere {
                         password passwordhere
                     }
                 }
                 mode local
             }
             client-ip-pool {
                 start 10.0.1.171
                 stop 10.0.1.180
             }
             dns-servers {
                 server-1 10.0.1.1
             }
             ipsec-settings {
                 authentication {
                     mode pre-shared-secret
                     pre-shared-secret keyhere
                 }
                 ike-lifetime 3600
             }
             mtu 1492
             outside-address 0.0.0.0
         }
     }
 }

Viewing all articles
Browse latest Browse all 20028

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>