Hey all. I'm new on the forums but years of cisco/nat/tcp experience.
I've got TWO XBOX 360 that need to connect to Xbox Live.
I've read all the multiple threads about port forwards, open firewall ports, disabling certain IPS sigs etc. Here's where I'm at:
I cannot get both Xbox to be in "Open" as opposed to "Moderate NAT" state. (if you're an Xbox live user, you know what this means).
One Xbox at a time is no problem at all.
Clearly the NAT rules to forward certain external facing tcp/udp ports (3074/88 etc) can't be told to go to multiple Xboxes, I understand this.
In an effort to fix this problem, I elected to put TWO external facing (WAN) NIC's in the UTM and basically dedicate the NAT port forward rules on each Wan Nic to each XBOX.
In order to use both NICs, I have to setup Uplink Balancing.
So I get all that setup, and using SNAT, I have Xbox1 sending outbound traffic out Wan1, and Xbox2 sending outbound traffic out Wan2. I configure all the appropriate inbound NAT rules to have Wan1 redirect the various Xbox live ports to Xbox1, and Wan2 redirect the various Xbox live ports to Xbox2.
And STILL I can only get 1 Xbox to be "open" and the other to be "Moderate Nat"!!!
I have Web filtering turned off
I have IPS turned off
I am defining the following Xbox live ports: TCP/UDP 3074, UDP 88, TCP/UDP 1026 (this last one I added recently as I have seen this "CAP port" hit the firewall from Xbox Live IPs when doing the connectivity test, I have no idea why, but I'm reaching)
I don't see any "dropped" firewall packets that would lead me to believe I'm blocking something I shouldn't be. I see my NAT rules get used as expected when I run the tests and view the live logs.
I'm about 2 days away from just saying screw-it and hardwiring the Xbox's directly to the un-firewalled ISP. But I really don't want to do that.
I'm clearly missing some understanding of something going on in the firewall, or something with Xbox Live in particular that I'm missing.
Does anyone have any suggestions?
Thanks in advance.
This thread was automatically locked due to age.