Double NAT issue. Trouble accessing cams on separate LAN

Bizentech

Getting the hang of it
Joined
Nov 17, 2015
Messages
105
Reaction score
9
Hello all

I am having trouble accessing cameras from a different building on the property that has a separate Network. Cameras are behind that network. They used to be accessible when the whole property was on the same LAN but for obvious reasons, they wanted completely separate networks under 1 ISP. Inherited this mess from whoever set this up previously

Here’s the topology:

Building 1. DEMARCATION
10.1.10.1/24 Comcast business equipment
Plus unmanaged switch for devices
3 cameras on this side, obviously work fine
No problems on this lan.
Ubiquiti wireless bridge between here and Building 2.

Building 2. Bridge connects to unmanaged switch.
Also 2 cameras connected. Status of cameras unknown yet… don’t care cause they need to be replaced anyway.
Still under 10.1.10.1 network
CAT6 burial feeding to Building 3.

building 3.
WAN is a LAN IP address from the 10.1.10.1 LAN network going into some residential type ASUS router and from router to a Cisco POE switch. Don’t recall exact LAN IP. But on this side of the network, everything is configured on a 172.16.0.1/24 network. Including the cameras. Asus handling DHCP on this end.

Now, I cannot see the cameras on the 10.1 side nor can I see the 10.1 side cameras on the 172.16 side.
ONLY way I can see the other LAN devices is if I change my computers IP address and gateway to match the lan I’m searching on.
Physically separating the LANs to a LAN1 and LAN2 via hardware is not an option and I don’t know if Comcast does VLAN so that’s out of the picture as well. could probably resolve some issues with port forwarding. Thoughts?? I’m banging my head against a wall trying to resolve this NATting garbage
 

Flintstone61

Known around here
Joined
Feb 4, 2020
Messages
6,640
Reaction score
10,977
Location
Minnesota USA
I wonder if it would be ok to let the Comcast business router do the DHCP for the Bldg 3, and still have a slightly diff IP scheme but in the 10 class that might allow you cam access? and put Asus router into Bridge mode? only thing is, everything over there would need to be reset IP wise. I'd want everybody to get on board with the 10.... addresses....
Long term solution probably....
somebody smarter than Johnny 5 pack will come along with an idea....
 

Bizentech

Getting the hang of it
Joined
Nov 17, 2015
Messages
105
Reaction score
9
Request to separate LAN’s was the request of property owner. And for obvious reasons because building 1 is residential, building 2 and 3 are on the commercial side.

the 172 side has 12 devices with the potential to 150 devices from the AP’s (when events are hosted)
 

Flintstone61

Known around here
Joined
Feb 4, 2020
Messages
6,640
Reaction score
10,977
Location
Minnesota USA
I forgot most of the 6 months of Cisco Net Acad,,,,that I took in 2000...LOL......wish I had a quick fix.....I'm sure there is one.....
 

Bizentech

Getting the hang of it
Joined
Nov 17, 2015
Messages
105
Reaction score
9
This only Cisco device on the network is a switch, on the 172.16 side, after the ASUS router, which is behaving as a managed L3 switch, with no VLANS or tagging or DHCP servers on any of the ports. All ports are basically trunks
 

Flintstone61

Known around here
Joined
Feb 4, 2020
Messages
6,640
Reaction score
10,977
Location
Minnesota USA
How about connecting the Bldg 3 camera's to Ubiquiti Airmax Nano Stations? 1 at the nearest switch in the 10.10 network and 1 on Bldg 3. then all the 172. stuff can go happily along....while you do an end around with a Cam data link.
 

Bizentech

Getting the hang of it
Joined
Nov 17, 2015
Messages
105
Reaction score
9
How about connecting the Bldg 3 camera's to Ubiquiti Airmax Nano Stations? 1 at the nearest switch in the 10.10 network and 1 on Bldg 3. then all the 172. stuff can go happily along....while you do an end around with a Cam data link.
You know what, you just gave me an idea… I’ll put the Cisco switch BEFORE the ASUS router and have the cameras on the 10.1 network from the switch and the ASUS plugged into the switch, isolating the ASUS and it’s devices to a 172.16 network
This should resolve the double NAT!
Ill keep you posted
 
Top