Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Enthusiast Zone > Networking > Firewall Help?

Firewall Help?
Thread Tools
zerostar
Mac Elite
Join Date: Jan 2005
Status: Offline
Reply With Quote
Mar 27, 2008, 01:34 PM
 
Not sure if anyone is familiar with watch-guard products... but here is my dilemma...

We have setup a firebox X500 as a nat/firewall, we have a few external IPs and those are setup to point to out mail server, ftp server & a terminal server.

When outside the network, mail on mail.ourdomain.com points correctly, I can use the imap, outlook webmail, the ftp server and the terminal all using external IPs.

When inside the network I can't get to anything with external IPs or the mail.ourdomain.com. I can get to it with the internal IP just fine.

The main problem right now is laptops/cell phones when they are on ethernet/wifi internally the mail is set to mail.ourdomain.com

How can I make this work going out to the internet and back in to the correct box? What are my options? We are running DHCP and DNS on a Win 2K3 SBS Box.

Thank you!
     
tridentinecanon
Registered User
Join Date: Feb 2008
Location: BIrmingham, AL
Status: Offline
Reply With Quote
Mar 27, 2008, 08:17 PM
 
Can you access the site (externally) via kproxy.com?
     
dimmer
Mac Enthusiast
Join Date: Feb 2006
Status: Offline
Reply With Quote
Mar 31, 2008, 03:43 PM
 
The most common way to handle this is via split-horizon DNS: which (basically) means that your DNS server understands the difference between internal and external client addresses and responds appropriately to the client with regards to it's origin IP. I'd suggest looking into that first, as there's no reason for your internal traffic to be hitting the firewall at all.

Alternatively, you could try mapping the ports on the firewall so that internal traffic heading for the "external" address gets rerouted to the correct internal addresses -- that's (IMHO) more cumbersome and difficult to troubleshoot, if you can even get it to work.
     
   
 
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Top
Privacy Policy
All times are GMT -4. The time now is 06:34 AM.
All contents of these forums © 1995-2017 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.8 © 2000-2017, Jelsoft Enterprises Ltd.,