Public IPs for both WANs are not reachable from Internet

Uzair
Here to help

Public IPs for both WANs are not reachable from Internet

WANs.JPGfirewall.JPGWAN flow.JPGAfter SD-WAN & Traffic shaping config. for dual WANs connections, NATs are also added successfully for both WANs. our Static Public IPs for both WANs are still not reachable. can some one identify the reason and share some solution..?

Plus: from locally connected to same LANs can ping and login to both Static IPs. only face outside traffic.

Thanks !

14 Replies 14
Ryan_Miles
Meraki Employee
Meraki Employee

Is your server 192.168.1.94 configured with its default gateway pointing to the MX IP 192.168.1.2?

An easy test is ping the host from other source interfaces of your MX besides the subnet the host is on (192.168.1.0/24). If that fails that likely means your host isn't actually using the correct gateway IP (192.168.1.2).

Ryan

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
Uzair
Here to help

i will work on it tomorrow after getting access to the server. thanks !

will update here if it help me.

Uzair
Here to help

i have set gw 192.168.1.2 for server then tried DNS and without DNS, still no outside traffic is working to server. server is unable to talk to the world except LAN.

Our wifi devices on network DHCP are connected to Internet successfully and communicate to the world.

Wifi devices on DHCP are using 192.168.1.2 gw and DNS as 8.8.8.8

cmr
Kind of a big deal
Kind of a big deal

What is between the MX and the internet?  Something is translating the public IPs to the 192 addresses shown on the WAN ports.

If my answer solves your problem please click Accept as Solution so others can benefit from it.
cmr
Kind of a big deal
Kind of a big deal

Your IPv6 address on WAN2 is pingable from the internet, so at least that works.

If my answer solves your problem please click Accept as Solution so others can benefit from it.
Uzair
Here to help

WAN2 public IP is only pingable, not working on accessing thru remote login (RDP).

Uzair
Here to help

WANs are directly connected to MX. wan1 wan2. --> then our office network.

ERP server is on same network on 192.xx

both WANs ISP have provided public IPs to access our ERP server from outside world.

thats the story!

thnx

cmr
Kind of a big deal
Kind of a big deal

What are your subnet masks, everything seems to be on a 192.168.1.x address, whether it be on the WAN or LAN side?  Are the MXs in passthru mode?

If my answer solves your problem please click Accept as Solution so others can benefit from it.
Uzair
Here to help

ANS1.JPGANS2.JPG

cmr
Kind of a big deal
Kind of a big deal

From above, your WANs also appears to be on 192.168.1.x networks, I'd change either the LAN or WAN IP address ranges to not overlap.

1000009537.jpg

If my answer solves your problem please click Accept as Solution so others can benefit from it.
Uzair
Here to help

i will work changing for WANs IP addresses to avoid overlaps. thanks !!

cmr
Kind of a big deal
Kind of a big deal

@Uzair have you changed the WAN IP addresses yet?  What device gives them that address, the ISP NTE?

If my answer solves your problem please click Accept as Solution so others can benefit from it.
BlakeRichardson
Kind of a big deal
Kind of a big deal

You appear to be using private IP addresses for WAN IP, these will not be accessible externally unless whatever is setup between your MX and the internet is setup for port forwarding. 

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
Uzair
Here to help

Thanks for your kind suggestion, can you briefly explain what should i do next? how to set - reconfigure to make public IP accessible through external world ? if you could guide me in steps for correction this configuration pls..

 

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels