IX. NAT Related Features
ExpiredConfiguring non-NAT operation (public subnet) with a Vigor 3900 / 2960
If you have multiple public IP addresses (i.e. a subnet allocated by your ISP as opposed to just a single IP address), it is possible to configure the DrayTek units that support multiple IP's in a flexible way using NAT, Multi-NAT/WAN IP Alias and IP Routing. The preferred method is often to use WAN IP Alias to minimise the direct exposure from unsolicitied incoming traffic via NAT but a non-NAT configure can also be setup.
Using IP Routing, IP Addresses can be routed directly through to the LAN side directly without applying NAT to that traffic, which can be useful for placing servers or other devices behind the router; This configuration would mean that the device uses a public IP Address directly.
IP Routing can be used in addition to the WAN IP Alias feature, but IP addresses allocated as IP Aliases are removed from the pool of addresses usable by the IP routed subnet.
This guide will use 198.51.100.152 as the Network Address, with a 255.255.255.248 subnet mask, which has a usable IP range of 198.51.100.153 to 198.51.100.158.
The router will use 198.51.100.153 for the WAN interface.
The address 198.51.100.158 will be used for IP routing, clients on the network would use an IP address available in the usable range, with 198.51.100.158 as their gateway.
On the Vigor 3900 series, this requires:
- Configuring the WAN interface as normal
- Set up a LAN interface in Routed mode, either as a part of an existing NAT subnet or as a separate Routed network interface
- Set up the router's LAN/WAN ARP Proxy feature to link the LAN and WAN interfaces
There are two methods to set this up:
Dedicated LAN Interface - This uses a separate LAN interface in Routing mode to route the public IP addresses through, this requires either a dedicated LAN port on the router or the use of VLAN tags (on a separate switch)
NAT & Routed Shared LAN Interface - This would add the routed subnet to the existing NATted LAN interface, this is required if the devices will be on the same physical network and VLAN tags are not in use
- First Published: 06/01/2015
- Last Updated: 16/06/2020