hi all,
i have this lan-situation: http://www.zebis.ch/dualwan.gif
all traffic from clients must go out -> wan1
all traffic from webserver (dmz2) must go out -> wan2
all outside traffic with destination to webserver will come in -> wan2
on my FG-A100 2.08MR12 i did this with:
- a static default route on each wan
- and one policy route " incoming dmz2, outgoing wan2, src/dst 0.0.0.0/0.0.0.0"
this worked fine since i made a update to 3.0 MR7P2
since that, some clients cannot go out. sniffering the FW tells me,
the FW will drop ip-pakets... when i shut down wan2, everything works fine,
but our webserver is off-line from the outside world....
any ideea how to solve this routing? i konw it can be done with
vdom, but this means e complet redraw of the network, which i
will do later...
thanx, claudio