Re: gpl digest, Vol 1 #1264 - 1 msg
"Drew S. Dupont" <dsdupont-cRNsNxxcKCstbC/[email protected]> Sat, 13 Nov 2004 09:05:57 -0500
| Newsgroups | gmane.comp.security.firewalls.smoothwall.general |
|---|---|
| Message-ID | <p06110415bdbbc53fea97@[192.168.250.50]> |
>Message: 1 >Date: Fri, 12 Nov 2004 17:52:02 -0500 >From: Richard Doiron <[email protected]> >To: <[email protected]> >Subject: [gpl] Question about MS Exchange and Smoothwall Express > >Hi, > >I have a need to set up Exchange 2003 on a private lan with users who need >access to the Exchange server from both from the private lan and the >internet. I have port forwarding set up so that a user can access the >Exchange server fine from the internet using the public address of the >Smoothwall. Similarly, users on the private lan get their Exchange fix using >the private address of the exchange server. > >The problem comes in with laptop users. If they set up their Exchange >account to use the private lan address, when out of the office nothing >works. If they set up the Exchange account to use the public address of the >Smoothwall, being out of the office works, but when inside, the Smoothwall >is discarding all packets (Martians?). > >The old setup used a Symantec Firewall VPN 200r and it worked in this >configuration. > > Setting up an Orange segment is not feasible as the client only has one box >to run server and exchange. > >Any help would be appreciated. > >Richard > >--__--__-- Add the external IP and/or name (depending on which, if not both, are setup for use) to the SW's /etc/hosts file and restart the DNS proxy (just restart SW or run a kill and dnsmasq with the right options). That way, if the laptop users try to get to the server suing the public IP outside your LAN, it works, and if they try inside the LAN, it will resolve to the local IP. This will only work if SW is the DNS server (or in the DNS call chain). If not, then add it to the local DNS server the laptop users get their DNS from. You would add something like the following to the hosts file if you do it in SW: <internal ip><tab><external ip> <internal ip><tab><hostname> NetWhiz -- ------------------------------------------------------------------------------------------------------ Drew S. Dupont dsdupont-cRNsNxxcKCstbC/[email protected] AIM: NetWhizOne FWD #: 271144 YIM: dsdupont ------------------------------------------------------------------------------------------------------ _______________________________________________ gpl mailing list [email protected] http://lists.smoothwall.org/mailman/listinfo/gpl SmoothWall Stash - Buy Our Stuff! http://cafepress.com/smoothwall