I have a wireless network with all wireless interfaces (CPE´s and AP´s) with fixed ip addresses in 10.50.60.0/24 network. Client PC´s get ip from DHCP server on Gateway 172.25.30.1 in the 172.25.30.0/24 range. All MT interfaces (AP´s and CPE´s) also have ip adresses (fixed) in this 172.25.30 network.
Everything fine so far, everything works. I can reach all my AP´s and CPE´s (except 1, see next) and all Clients can browse the internet. Ping times are all in matter of 1 ms up to an occasional 20 or 30´er.
I have now 1 new MT rb535 CPE with ip 172.25.30.53 and ip 10.50.60.53 on wlan1 interface and the eth interface has 192.168.50.1 and has DHCP running on it assigning ip addresses in that same network to client PC´s.
I have set up src-nat and dst-nat same as other CPE working fine but off course other ip for itself. I also checked routing table which is same as this other CPE working fine (but with its ip´s). As far as I can see (comparing with the other working CPE) all settings are OK.
I can mac ping the CPE from its connected AP, I can mac telnet in that CPE. The unit comes up in Winbox (remote, after 5 hops) but only after some time. But in winbox I CANNOT reach it, not by mac nor by any of the two ip adresses!
If logged in by mac-telnet from its AccessPoint I can ip-ping back the AP and I can ping the Gateway with very good results.
So it looks outgoing traffic is fine, but incoming to that CPE is not possible on IP level.
If I ping the unit from it´s AP on the 172.25.30.53 address I get timeouts on that adress, or ¨host unreachable¨ on 10.50.60.1 (which is the gateway) or a 4ms return from the gateway (10.50.60.1)!!
If I ping the unit from it´s AP on the 10.50.60.53 address I get timeouts or 10.50.60.50 (wlan of the AP) telling me the host is unreachable.
The AP has its interfaces bridged so both wlan1 and Eth. carry both ip adresses in the two different networks. Both radios have forwarding on and also in the access list forwarding is enabled.
What am I doing wrong? I need access to the unit by ip to update the firmware and am not sure if client is able to surf the internet now.
Why can I not ip-ping the CPE from the network! (The client can ping it from within the DHCP network.)
I am not looking for an answer like ¨read the manual¨ or look in the WiKi. I´ve been doing this all day. I wan´t suggestions on what I might be overlooking.
Could it be the difference in the firmware versions? All units are on 2.9.41 except this CPE which is still in 2.9.38.
rgds.