Re: Issues with setting up a port-forwarding rule

Spyros Tsiolis <stsiol-/[email protected]>
Newsgroups gmane.comp.security.ipcop.user
Message-ID <[email protected]>
--------------------------------------------
On Tue, 26/7/16, Bob Evans <[email protected]> wrote:

 Subject: Re: [IPCop-user] Issues with setting up a port-forwarding rule
 To: [email protected]
 Date: Tuesday, 26 July, 2016, 15:19
 
 In article
 <[email protected]>,
 Spyros
 Tsiolis <[email protected]>
 wrote
 >1. Simple IpCop v2.1.9
 installation with RED and GREEN
 >( no
 ORANGE, no BLUE).
 >
 >2. ISP IP address is static
 >
 >3. Internal GREEN
 Network AT 192.168.20.0/24
 >
 >I have a machine at 192.168.20.2 that runs
 https and would
 > like to make it
 viewable for my client from the outside world.
 >I would prefer for the client to point the
 browser at a
 >non-standard port number
 (say, 33443) , then internaly route
 >that
 number to 443 (https) :
 >
 >I am trying to setup a rule on Firewall -
 Port Forward :
 >
 >SOURCE :
 >     
 ADDRESS : ANY
 >
 >IPCOP
 EXTERNAL DESTINATION :
 > 
    Alias IP : RED ADDRESS
 > 
    Custom Services (CHECKED) : HTTPHIGH (mapped
 at "custom rules" at 33443)
 >
 >INTERNAL DESTINATION
 :
 >     INTERNAL NETWORK
 >     Default Interfaces :
 GREEN
 >     Destination IP :
 192.168.20.2
 >     Default
 Services : https (443)
 >
 >It doesn't work .
 
 It looks like it should work (assuming that the
 custom service HTTPHIGH
 is valid for TCP).
 Have you checked the networking basics?
 
 For example:
  -  Is the
 gateway address of the server at 192.168.20.2 set to the
     address of IPCop's green port?
  -  Can you ping the server from IPCop?
  -  Is there any possibility that the ISP
 might be blocking inbound TCP
    
 connections to non-standard / any ports?
 
 Might be worth trying a quick test with the
 forwarding rule input
 service temporarily
 set to HTTPS (to accept connections on port 443).
 
 I am sure that you realise
 that you cannot test RED->GREEN forwarding
 from inside of the Green network - you must
 connect from the Internet
 side :)
 
 HTH,
 -- 
 Bob Evans
 --------------------------------------------

Hi Bob,

Sorry for the late reply.
Yes, I 've checked everything.
I tried other services on known ports like ssh from the real
world port 22 to inside port 22 and so on.
Nothing works.

There is something genuinely disturbing about this specific
IpCop installation.

Oh well.
With v1.4.x it was pretty straight forward.
Nowadays , I can't get anything to work with v2.x

No worries. I am taking it offline in a couple of days and
will install a mikrotik router.

Thank you very much for your kind reply.

Regards,

spyros




------------------------------------------------------------------------------
_______________________________________________
IPCop-user mailing list
[email protected]
Manage your subscription or unsubscribe
https://lists.sourceforge.net/lists/listinfo/ipcop-user
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.