The primary router is a Huawei F670 acquired from the ISP and the secondary router is in a NSA Sonicwall firewall.
Yes, I've read this post and this post yet I didn't understand a thing.
This is my simplified network architecture
I've already configured a Nat policy in the NSA that goes from the primary router(192.168.1.1, 123.11.123.11) to the server (10.1.0.125) on port xxxx and the reverse policy.
I've already configured the firewall rules in the NSA that allows connection from the primary router to 0.125 and the reverse rules.
I've already configured port forwarding rules in the primary router to forward port 2234 from the public IP directly to 10.1.0.125
The situation is now anything on the internet unable to access my server on port 2234, nor the clients in the primary router network.
But 10.1.0.121 could ping all of the network clients above them and could access my server through port 2334 through my router Public IP.
I suspect there is a problem with the F670 configuration that disables the connection to the child network, or the F670 doesn;'t know how to get to 10.1.0.125. Yet I don't know how to fix it.
Any help would be apprecited, thanks!