[Help needed]Creating DMZ on ER605

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

[Help needed]Creating DMZ on ER605

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
[Help needed]Creating DMZ on ER605
[Help needed]Creating DMZ on ER605
2023-11-08 00:48:52 - last edited 2023-11-10 06:42:27
Model: ER605 (TL-R605)  
Hardware Version: V1
Firmware Version: 1.1.1 Build 20210723 Rel.64608

Hi all,

I just purchased an TPLink ER605 V1 router for my home network and have some issues, can you please help me?

 

CURRENT SETUP

I divided network to 2 subnets:

A: 192.168.1.0/24 for all home devices (laptop, phones...)

and

B: 10.0.0.0/24 for home servers

The network diagram is as follows:

r/TpLink - Help need for creating DMZ on ER605

my network

modem 192.168.1.1 routing table:

r/TpLink - Help need for creating DMZ on ER605

server IP is 10.0.0.11.

I would like to expose server from subnet B to all devices in sub net A.

Current DMZ config on ER605:

r/TpLink - Help need for creating DMZ on ER605

 

ISSUESI cannot ping server from machines in network A:

r/TpLink - Help need for creating DMZ on ER605

From the line " Redirect Host", I think the modem is doing its job by re-routing packages to ER605, but then there is no response for pinging.

traceroute cmd produces same result, being stopped at 192.168.1.100 (ER605 wan interface)

This is the route table from ER605:

r/TpLink - Help need for creating DMZ on ER605

Server from net B can reach the internet, can ping youtube or google.

May I know where did I go wrong in configuration? Because DMZ should already exposed the server right?

  0      
  0      
#1
Options
2 Accepted Solutions
Re:[Help needed]Creating DMZ on ER605-Solution
2023-11-08 02:55:47 - last edited 2023-11-10 06:42:29

Hi @tom168 

Thanks for posting in our business forum.

Set up the port forwarding first.

How to set up Port Forwarding feature on TP-Link SMB Router (new UI)

Troubleshooting Virtual Services(Port Forwarding) on the Router Doesn't Take Effect

 

So if you need to access the server in 10.0.0.1/24, you should port forward on the ER605. If you gonna expose it on the Internet, you should port forward twice. On ER605 and your 192.168.1.1 router.

When you port forward on 192.168.1.1, you should port forward the IP address of the ER605(WAN IP). Then this tunnels into the ER605 from the public Internet.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
Recommended Solution
  0  
  0  
#2
Options
Re:[Help needed]Creating DMZ on ER605-Solution
2023-11-08 03:56:18 - last edited 2023-11-10 06:42:27

Hi @tom168 

Thanks for posting in our business forum.

tom168 wrote

  @Clive_A 
Thank you for your reply.
I dont desire to expose my server to internet, just to another subnet.
I tried port fordwarding on the ER605 and network A can ping server, so it means the config on ISP issued modem is good.

 

However, port forwarding solution is not good for me since I need to expose all ports on server and I have many servers (3 of them).
Is there anyway to just expose all LAN to WAN on ER605? This is a closed-environment so I dont really worry about security here.

 

DMZ is the same as the port forwarding. Just set all ports open if the server in B got that port available. You should DMZ on the ER605. It should work as expected. If no, reboot and try again.

 

But you cannot forward all LAN to WAN. ER605 is a router. NAT cannot be disabled.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
Recommended Solution
  0  
  0  
#4
Options
3 Reply
Re:[Help needed]Creating DMZ on ER605-Solution
2023-11-08 02:55:47 - last edited 2023-11-10 06:42:29

Hi @tom168 

Thanks for posting in our business forum.

Set up the port forwarding first.

How to set up Port Forwarding feature on TP-Link SMB Router (new UI)

Troubleshooting Virtual Services(Port Forwarding) on the Router Doesn't Take Effect

 

So if you need to access the server in 10.0.0.1/24, you should port forward on the ER605. If you gonna expose it on the Internet, you should port forward twice. On ER605 and your 192.168.1.1 router.

When you port forward on 192.168.1.1, you should port forward the IP address of the ER605(WAN IP). Then this tunnels into the ER605 from the public Internet.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
Recommended Solution
  0  
  0  
#2
Options
Re:[Help needed]Creating DMZ on ER605
2023-11-08 03:34:44

  @Clive_A 
Thank you for your reply.
I dont desire to expose my server to internet, just to another subnet.
I tried port fordwarding on the ER605 and network A can ping server, so it means the config on ISP issued modem is good.

 

However, port forwarding solution is not good for me since I need to expose all ports on server and I have many servers (3 of them).
Is there anyway to just expose all LAN to WAN on ER605? This is a closed-environment so I dont really worry about security here.

 

  0  
  0  
#3
Options
Re:[Help needed]Creating DMZ on ER605-Solution
2023-11-08 03:56:18 - last edited 2023-11-10 06:42:27

Hi @tom168 

Thanks for posting in our business forum.

tom168 wrote

  @Clive_A 
Thank you for your reply.
I dont desire to expose my server to internet, just to another subnet.
I tried port fordwarding on the ER605 and network A can ping server, so it means the config on ISP issued modem is good.

 

However, port forwarding solution is not good for me since I need to expose all ports on server and I have many servers (3 of them).
Is there anyway to just expose all LAN to WAN on ER605? This is a closed-environment so I dont really worry about security here.

 

DMZ is the same as the port forwarding. Just set all ports open if the server in B got that port available. You should DMZ on the ER605. It should work as expected. If no, reboot and try again.

 

But you cannot forward all LAN to WAN. ER605 is a router. NAT cannot be disabled.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
Recommended Solution
  0  
  0  
#4
Options