Web Host Chat
Bringing Hosts & Customers together since 2001
Home QLinks Members Your Profile Register FAQ's Hosts Only Area SMS Alerts Advertising
User Information
»REGISTER NOW!

Go Back   Web Host Chat > Web Hosting Chat > Business and Technical Advice
Reply
 
LinkBack Thread Tools
Old 6th October 2008   #1 (permalink)
I am Staff at
Mooharr
About My Company!


Certified Host
Join Date: Jun 2003
Posts: 1,694
JamesSykes is on a distinguished road
What's going on here - DMZ + Routing Issues

I've got a very simple network setup :

Local Network : 192.168.0.0/24
DMZ : 10.10.10.0/24

I've got a server on the DMZ and a rule setup on the firewall to send HTTP traffic to it. It all works well for external users.

The issue is from within the local network. When you try to reach the server using the public IP address you can't get through. If you use the local address then it works just fine. You just cant use the public address.

I've got a rule temporarily in place that allows full access between the DMZ and Local Network so that's not an issue.

Just wanted to check encase it's a really obviously stupid thing going on here. I'm guessing yes.
__________________
Mooharr
E-Mail Hosting Services

These are not my views and i cannot be held accountable for anything he says.
__________________
Web Host - VIP Member
JamesSykes is offline   Reply With Quote
Old 6th October 2008   #2 (permalink)
I am Staff at
KDA Web Services Ltd
About My Company!


Certified Host
Karl's Avatar
Join Date: Nov 2001
Location: Derbyshire
Posts: 5,965
Karl is on a distinguished road
AFAIK that's perfectly standard behaviour that the LAN can't talk to the DMZ on the public IP address as you'd have a 3-way NAT going on.
__________________
Karl Austin :: Owner :: Director :: Admin :: Tea Boy
KDA Web Services Ltd. :: 0800 542 9764 :: Company: 04114724 :: VAT: GB 842 9597 81
"Individual Solutions for Individual Customers" - Call us today for free

Only two things are infinite, the universe and human stupidity, and I'm not sure about the former. - Einstein
__________________
Web Host - VIP Member
Karl is offline   Reply With Quote
Old 6th October 2008   #3 (permalink)
Registered User (13)
Welcome aboard!
Join Date: Aug 2008
Location: London, UK
Age: 31
Posts: 10
Trikkitt is on a distinguished road
I've always hit the same problem myself. The only fix I can think of is to use DNS names. On a small network of a couple of PCs just modify the HOSTS files on Windows computers, put the name and the DMZ address. On larger networks messing around with the DNS server can create a fix.

You should be able to create a similar rule for LAN users to access the DMZ only on port 80/443 to stop open access.

Michael
__________________
Registered User
Trikkitt is offline   Reply With Quote
Old 6th October 2008   #4 (permalink)
I am Staff at
C.C.S. Leeds Ltd
About My Company!

Certified Host
Join Date: Sep 2005
Location: Leeds
Posts: 395
PeteK is on a distinguished road
What device is the DMZ setup on. Most have a nat loopback option to sort it. If its something Cisco then I can give you the command set, the rest would just be generic help!
__________________
CCS Leeds Ltd

Company reg: 03507910 VAT reg: GB 698 2027 05
------------------------------------------------
For all your Broadband / DSL, MLPPP Bonded, Leased Lines
and Web Hosting needs why not pop over to CCS Leeds Ltd

------------------------------------------------
__________________
Web Host - Certified Member
PeteK is offline   Reply With Quote
Old 7th October 2008   #5 (permalink)
I am Staff at
Secura Hosting Ltd
About My Company!


Certified Host
markcastle's Avatar
Join Date: Aug 2002
Location: London, England
Posts: 3,042
markcastle is on a distinguished road
Out Packets: Client: 192.168.0.x --> NAT --> Public IP --> NAT --> DMZ: 10.10.10.x
Return Packets: DMZ: 10.10.10.x --> NAT --> Public IP --> NAT --> Client: 192.168.0.x

....not pretty.
__________________
••• Mark Castle ••• Secura Hosting Ltd •••
••• Managed Hosting •••
••• AS29452UK Company Reg No: 04330657VAT Number: 789 2703 81Sales: 0845 123 2632 •••
My views are my own and not those of my company.
__________________
Web Host - VIP Member
markcastle is online now   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Routing assistance.. LeaUK Business and Technical Advice 12 14th May 2008 08:25 PM
OpenBSD routing tommy2 Business and Technical Advice 6 7th December 2004 12:54 PM
routing/peering Scott Business and Technical Advice 39 8th December 2003 01:30 PM


Some great companies!


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0