Welcome, Guest. Please login or register.
Did you miss your activation email?
Tuesday 30 April 2024, 10:39:58 am

Login with username, password and session length

Visit the Official Endian Reference Manual  HERE
14247 Posts in 4376 Topics by 6493 Members
Latest Member: thiagodod
Search:     Advanced search
+  EFW Support
|-+  Support
| |-+  General Support
| | |-+  Port Forwarding from Red to Green
0 Members and 0 Guests are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: Port Forwarding from Red to Green  (Read 26241 times)
rdbates
Jr. Member
*
Offline Offline

Posts: 4


« on: Wednesday 04 November 2009, 01:06:17 pm »

Let me start by saying I'm an Endian "noob".  Cry

I've setup plenty of firewalls in the past, each has their own quirks, and I'm having trouble setting up a basic port forward/translate to allow users Terminal Services access.

I setup a  rules in Destination Port Forwarding, one to translate incoming from RED on port 33890/TCP to SERVER1 on the GREEN network on port 3389 and another to translate incoming from RED on 33891/TCP to SERVER2 on the GREEN network on port 3389.

My question is this: Is there some other master setting which is blocking the forwarding that I'm missing?  Does what I described sound right?

Any suggestions would be greatly appreciated.

Thanks!

Rich Bates
Logged
bayross
Full Member
***
Offline Offline

Gender: Male
Posts: 23


« Reply #1 on: Thursday 05 November 2009, 02:28:14 am »

You also need to create a rule under "System Access", otherwise it will not work.
Garrett
Logged
rdbates
Jr. Member
*
Offline Offline

Posts: 4


« Reply #2 on: Thursday 05 November 2009, 03:57:46 am »

You also need to create a rule under "System Access", otherwise it will not work.
Garrett

Thanks for the help - tried it - still having a problem.

Do I need to setup a Source NAT for comm back outside?  How about rules under Incoming Routed Traffic?

I have yet to successfully setup any port forwarding ad my boss is getting itchy

PS: Once I get any port forwarding working I assume I can setup 10443 for HTTPS management from the outside world?
Logged
bayross
Full Member
***
Offline Offline

Gender: Male
Posts: 23


« Reply #3 on: Thursday 05 November 2009, 04:05:49 am »

I wouldnt recommend making you Firewall GUI accessible to the outside world. If anything set it up so you VPN into your network and then connect to the EFW.
Try this... just alter the ports, etc as necessary.

In Firewall, configure a Destination NAT rule as follows:
Access: ANY Uplink
Target: ANY Uplink
Service HTTP
Protocol: TCP
Target: 80
Translate to: TYPE IP
DNAT Policy: NAT
IP: {WEBSERVER IP on GREEN INTERFACE}
Port Range: 80

Save and apply rule

Then go to Firewall, configure System Access rule as follows:
Source Address: {leave blank}
Source Interface: RED
Service HTTP
Protocol: TCP
Target: 80
Policy: ACTION "ALLOW"

Save and apply and you should be good to go. You will now be able to access the specified server externally (Red zone to green zone)

Garrett
Logged
rdbates
Jr. Member
*
Offline Offline

Posts: 4


« Reply #4 on: Thursday 05 November 2009, 04:55:30 am »

I wouldnt recommend making you Firewall GUI accessible to the outside world. If anything set it up so you VPN into your network and then connect to the EFW.
Try this... just alter the ports, etc as necessary.

In Firewall, configure a Destination NAT rule as follows:
Access: ANY Uplink
Target: ANY Uplink
Service HTTP
Protocol: TCP
Target: 80
Translate to: TYPE IP
DNAT Policy: NAT
IP: {WEBSERVER IP on GREEN INTERFACE}
Port Range: 80

Save and apply rule

Then go to Firewall, configure System Access rule as follows:
Source Address: {leave blank}
Source Interface: RED
Service HTTP
Protocol: TCP
Target: 80
Policy: ACTION "ALLOW"

Save and apply and you should be good to go. You will now be able to access the specified server externally (Red zone to green zone)

Garrett

PROBLEM SOLVED!!!!!

Thanks alot for your help!
Logged
bayross
Full Member
***
Offline Offline

Gender: Male
Posts: 23


« Reply #5 on: Thursday 05 November 2009, 04:56:01 am »

No problem, glad to help out.
Logged
gdPAC
Full Member
***
Offline Offline

Gender: Male
Posts: 12



« Reply #6 on: Thursday 05 November 2009, 07:27:32 am »

System access rules grant access to the Endian Firewall itself.  You just instructed him to give port 80 access to the EFW from the Internet.  I don't think that's recommended.

Glen
Logged
bayross
Full Member
***
Offline Offline

Gender: Male
Posts: 23


« Reply #7 on: Thursday 05 November 2009, 11:50:52 pm »

You are right!! My mistake, just disable system access rules and you should be good.
Logged
vikash
Jr. Member
*
Offline Offline

Posts: 5


« Reply #8 on: Tuesday 17 November 2009, 10:26:50 pm »

Interfaces : 2 - GREEN and RED (PPPoE)
WAN (RED) : Dynamic IP PPPoE
LAN (GREEN) : 192.168.1.0/24

Local server on GREEN interface IP : 192.168.1.10
Services to be forwarded WAN2LAN : HTTP, HTTPS, SSH, FTP

Dynamic DNS with wildcard www.host.dyndns.org -> Uplink main IP (RED).

Hi, Ive been trying to do the same thing, and the Destination NAT worked for me. Thanks!

However I cannot access my webserver from with-in the GREEN network (ie. my PC) using the external address. I believe its called loopback NAT. This usually works by default using an off the shelf BB router such as linksys/dlink/etc.

Any idea on how to enable this? Ive tested this on EFW 2.3 and 2.2 with same results.

Thanks.
Vikash.
Logged
vlongjvc
Full Member
***
Offline Offline

Posts: 27


« Reply #9 on: Monday 30 November 2009, 06:32:26 pm »

I have followed above instructions but the status of the connection is: SYN_SENT, the connection is failed  Angry. Have anyone face this issue? Port forwarding is a little bit complicated compare with version 2.2
Logged
vlongjvc
Full Member
***
Offline Offline

Posts: 27


« Reply #10 on: Tuesday 01 December 2009, 01:28:44 pm »

Following the instructions from here (http://bugs.endian.com/view.php?id=2191) and my ploblem is solved. Thanks Peter, now Endian 2.3 works perfectly for me!
Logged
jacklib
Jr. Member
*
Offline Offline

Posts: 3


« Reply #11 on: Friday 04 December 2009, 06:48:22 pm »

Can anybody please elaborate on how did they fix the loopback NAT? I tried Peter's suggestion to create a host entry with my Public IP but it doesn't work.

Logged
Pages: [1] Go Up Print 
« previous next »
Jump to:  

Page created in 0.094 seconds with 19 queries.
Powered by SMF 1.1 RC2 | SMF © 2001-2005, Lewis Media Design by 7dana.com