Re: Issues with setting up a port-forwarding rule

Bob Evans <ipcopu_list-za6GKHvPnsC+O/rFHDoEyJWNWR1az2d/Wmv/[email protected]>
Newsgroups gmane.comp.security.ipcop.user
Message-ID <[email protected]>
In article
<960790850.7209977.1469438749799.JavaMail.yahoo-sAHhhX/[email protected]>, Spyros
Tsiolis <stsiol-/[email protected]> wrote
>1. Simple IpCop v2.1.9 installation with RED and GREEN
>( no ORANGE, no BLUE).
>
>2. ISP IP address is static
>
>3. Internal GREEN Network AT 192.168.20.0/24
>
>I have a machine at 192.168.20.2 that runs https and would
> like to make it viewable for my client from the outside world.
>I would prefer for the client to point the browser at a
>non-standard port number (say, 33443) , then internaly route
>that number to 443 (https) :
>
>I am trying to setup a rule on Firewall - Port Forward :
>
>SOURCE :
>      ADDRESS : ANY
>
>IPCOP EXTERNAL DESTINATION :
>     Alias IP : RED ADDRESS
>     Custom Services (CHECKED) : HTTPHIGH (mapped at "custom rules" at 33443)
>
>INTERNAL DESTINATION :
>     INTERNAL NETWORK
>     Default Interfaces : GREEN
>     Destination IP : 192.168.20.2
>     Default Services : https (443)
>
>It doesn't work .

It looks like it should work (assuming that the custom service HTTPHIGH
is valid for TCP). Have you checked the networking basics?

For example:
 -  Is the gateway address of the server at 192.168.20.2 set to the
    address of IPCop's green port?
 -  Can you ping the server from IPCop?
 -  Is there any possibility that the ISP might be blocking inbound TCP
    connections to non-standard / any ports?

Might be worth trying a quick test with the forwarding rule input
service temporarily set to HTTPS (to accept connections on port 443).

I am sure that you realise that you cannot test RED->GREEN forwarding
from inside of the Green network - you must connect from the Internet
side :)

HTH,
-- 
Bob Evans

------------------------------------------------------------------------------
What NetFlow Analyzer can do for you? Monitors network bandwidth and traffic
patterns at an interface-level. Reveals which users, apps, and protocols are 
consuming the most bandwidth. Provides multi-vendor support for NetFlow, 
J-Flow, sFlow and other flows. Make informed decisions using capacity planning
reports.http://sdm.link/zohodev2dev
_______________________________________________
IPCop-user mailing list
[email protected]
Manage your subscription or unsubscribe
https://lists.sourceforge.net/lists/listinfo/ipcop-user
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.