hope you can help me solve the challenge I've been tasked with, when my old LTE-Router (serving WAN2) blew up two week ago.
In short:I need to find a way to provide WAN redundancy for my PBX/SIP System but avoid Dual NAT at all cost, to get a good availability of the voice-call service to the family.
Especially incoming calls would often not pass, when the PBX is connected via a double NAT (SIP-ALG helpers would not improve this, to my experience).
Where to start:I do run a Dual WAN setup (ISP1 - cable, ISP2 - LTE/4G) since a couple of years and it serves me well.
Both ISPs provide their Routers (so I have no right of way in terms of hardware and firmware choice).
As I was not able to switch off the firewalls in the ISP-Routers anyway, I decided to disable srcnat/masquerading rule/action in the firewall of my central home Router (a RB4011).
This left me in the position to run my central PBX from inside my home LAN and switching default gateways for WAN1 and WAN2 was transparent to the PBX (and that enabled the PBX to pass one NAT only for outbound internet traffic, to my SIP providers this way). My PBX is a standard device, providing DECT/SIP/analog/ISDN Telephony to the home (no Asterisk like PBX, no full blown OS)
The root cause of the new problem:The LTE-Router died two weeks ago. The replacement model, although having a new, superior 4G performance, is not able to accept an additional static route, pointing back to hosts (and the PBX hence) of my other home network(s). Thus I am left with/forced to enable NAT in my RB4011 for the default route using WAN2 as gateway (the new LTE Router).
这将结束在一个NAT的两倍situation, once WAN2 takes over....which is not acceptable for SIP services used by my PBX.
Where I am now:I now did place the PBX, along with both ISP Routers inside a dedicated VLAN, as a WAN zone on a single network (remember, both Routers do provide NAT, so the PBX inside that zone is still safe).
This would allow me to at least switch the default gateway inside the PBX manually to either WAN and maintain the single NAT status for each WAN Route.
For traffic from my home (V)LANs, I enabled NAT towards the LTE/WAN2 gateway in my RB4011, accepting double NAT for this route for other hosts (which do not have a problem with double NAT).
This scenario technically works and is depicted below.
The challenge:How can I enable the PBX, now in the WAN zone, to
- avoid dual NAT scenario when either WAN1 or WAN2 is active
- 使用一个默认网关,使切换of either WAN, transparently/without need for manual intervention
I am willing to redesign my network layout as needed, as per your suggestions, but am hoping that there is just some additional magic to add. ;-)
Many thanks in advance for your time and feedback!