Hi guys,
I have installed openwrt last version on my two devices Netgear R7500 and Tp Link Archer C7.
I have problem with portforwarding, upnp...
This is my configuration :
Internet ---- > MY ISP Huawei router in BRIDGE mode ---(lan to wan)--> Netgear R7500 (192.168.1.1 , dhcp on) ------ (lan to lan)---> Tp link Archer C7 (192.168.1.2 , dhcp off)
My macbook is connected to C7 and I get ip and everything from my Netgear. But when I add port forward in Netgear its not working, also not working when add specific port in both of them.
My UPNP service also not working, I have installed it on Netgear ofc.
Can you please help me ? What I need to do?
Here is screenshots of my interfaces on both routers
Netgear : https://ibb.co/VVTsTG3
Tp-link : https://ibb.co/dbKcR73
Pico
March 14, 2022, 11:07pm
2
first: preferrably post your config files, not screenshots. Take a look at other posts how people do that.
unclear: are you aiming at cascaded routers/double NAT?
Because if so, then this wont work:
vargapi:
192.168.1.1
192.168.1.2
looks like your 2 routers use the same subnet on the lan side. You would have to change one of them to 192.168.2.x or anything else but 192.168.1.x.
I will post config files when I get to my mac again ..
I want them to be on same subnet and only 1st router giving dhcp adressess? I think that is correct?
Second router only giving lan ports like a switch and wifi signal…
mk24
March 15, 2022, 1:59am
4
Your WAN IP is 100.120.X.X which means the ISP is doing Carrier Grade NAT on you. This means that incoming connections are not possible. For port forwarding to work, the WAN IP you get from the ISP needs to match the actual public IP that your Internet use goes out on, which is reported by "what's my IP" test sites.
Beyond that, since the Archer is a dumb AP, it doesn't route anything. All the endpoint machines in the house are in the Netgear's LAN, whether they are connected directly or (bridged at layer 2) via the TP-Link. You would only need to forward ports in the Netgear. But my first paragraph explains why that doesn't work.
4 Likes
I cant find how to copy config files, can you help me?
Backup config
Open archive
Open relevant file(s)
Copy
Paste
vargapi:
I fix that somehow?
Ask your IP for a Public IP . If that's available (likely not since they using CG-NAT in the first place), they will charge you.
1 Like
My config files:
dhcp
config dnsmasq
option domainneeded '1'
option boguspriv '1'
option filterwin2k '0'
option localise_queries '1'
option rebind_protection '1'
option rebind_localhost '1'
option local '/lan/'
option domain 'lan'
option expandhosts '1'
option nonegcache '0'
option authoritative '1'
option readethers '1'
option leasefile '/tmp/dhcp.leases'
option resolvfile '/tmp/resolv.conf.d/resolv.conf.auto'
option nonwildcard '1'
option localservice '1'
option ednspacket_max '1232'
config dhcp 'lan'
option interface 'lan'
option start '100'
option limit '150'
option leasetime '12h'
option dhcpv4 'server'
option dhcpv6 'server'
option ra 'server'
list ra_flags 'managed-config'
list ra_flags 'other-config'
config dhcp 'wan'
option interface 'wan'
option ignore '1'
config odhcpd 'odhcpd'
option maindhcp '0'
option leasefile '/tmp/hosts/odhcpd'
option leasetrigger '/usr/sbin/odhcpd-update'
option loglevel '4'
firewall
config defaults
option syn_flood '1'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'REJECT'
config zone
option name 'lan'
list network 'lan'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'ACCEPT'
config zone
option name 'wan'
list network 'wan'
list network 'wan6'
option input 'REJECT'
option output 'ACCEPT'
option forward 'REJECT'
option masq '1'
option mtu_fix '1'
config forwarding
option src 'lan'
option dest 'wan'
config rule
option name 'Allow-DHCP-Renew'
option src 'wan'
option proto 'udp'
option dest_port '68'
option target 'ACCEPT'
option family 'ipv4'
config rule
option name 'Allow-Ping'
option src 'wan'
option proto 'icmp'
option icmp_type 'echo-request'
option family 'ipv4'
option target 'ACCEPT'
config rule
option name 'Allow-IGMP'
option src 'wan'
option proto 'igmp'
option family 'ipv4'
option target 'ACCEPT'
config rule
option name 'Allow-DHCPv6'
option src 'wan'
option proto 'udp'
option src_ip 'fc00::/6'
option dest_ip 'fc00::/6'
option dest_port '546'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-MLD'
option src 'wan'
option proto 'icmp'
option src_ip 'fe80::/10'
list icmp_type '130/0'
list icmp_type '131/0'
list icmp_type '132/0'
list icmp_type '143/0'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-ICMPv6-Input'
option src 'wan'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
list icmp_type 'router-solicitation'
list icmp_type 'neighbour-solicitation'
list icmp_type 'router-advertisement'
list icmp_type 'neighbour-advertisement'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-ICMPv6-Forward'
option src 'wan'
option dest '*'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-IPSec-ESP'
option src 'wan'
option dest 'lan'
option proto 'esp'
option target 'ACCEPT'
config rule
option name 'Allow-ISAKMP'
option src 'wan'
option dest 'lan'
option dest_port '500'
option proto 'udp'
option target 'ACCEPT'
config rule
option name 'Support-UDP-Traceroute'
option src 'wan'
option dest_port '33434:33689'
option proto 'udp'
option family 'ipv4'
option target 'REJECT'
option enabled 'false'
config include
option path '/etc/firewall.user'
config include 'miniupnpd'
option type 'script'
option path '/usr/share/miniupnpd/firewall.include'
option family 'any'
option reload '1'
network
config interface 'loopback'
option device 'lo'
option proto 'static'
option ipaddr '127.0.0.1'
option netmask '255.0.0.0'
config globals 'globals'
option ula_prefix 'fdb8:c3f9:13c2::/48'
config device
option name 'br-lan'
option type 'bridge'
list ports 'eth1.1'
config interface 'lan'
option device 'br-lan'
option proto 'static'
option netmask '255.255.255.0'
option ip6assign '60'
option ipaddr '192.168.1.1'
config interface 'wan'
option device 'eth0.2'
option proto 'dhcp'
config interface 'wan6'
option device 'eth0.2'
option proto 'dhcpv6'
config switch
option name 'switch0'
option reset '1'
option enable_vlan '1'
config switch_vlan
option device 'switch0'
option vlan '1'
option ports '1 2 3 4 6t'
config switch_vlan
option device 'switch0'
option vlan '2'
option ports '5 0t'
system
Closed
March 25, 2022, 6:11pm
9
This topic was automatically closed 10 days after the last reply. New replies are no longer allowed.