Re: Issues with setting up a port-forwarding rule
Spyros Tsiolis <stsiol-/[email protected]>
| Newsgroups | gmane.comp.security.ipcop.user |
|---|---|
| Message-ID | <[email protected]> |
-------------------------------------------- On Tue, 26/7/16, Bob Evans <[email protected]> wrote: Subject: Re: [IPCop-user] Issues with setting up a port-forwarding rule To: [email protected] Date: Tuesday, 26 July, 2016, 15:19 In article <[email protected]>, Spyros Tsiolis <[email protected]> wrote >1. Simple IpCop v2.1.9 installation with RED and GREEN >( no ORANGE, no BLUE). > >2. ISP IP address is static > >3. Internal GREEN Network AT 192.168.20.0/24 > >I have a machine at 192.168.20.2 that runs https and would > like to make it viewable for my client from the outside world. >I would prefer for the client to point the browser at a >non-standard port number (say, 33443) , then internaly route >that number to 443 (https) : > >I am trying to setup a rule on Firewall - Port Forward : > >SOURCE : > ADDRESS : ANY > >IPCOP EXTERNAL DESTINATION : > Alias IP : RED ADDRESS > Custom Services (CHECKED) : HTTPHIGH (mapped at "custom rules" at 33443) > >INTERNAL DESTINATION : > INTERNAL NETWORK > Default Interfaces : GREEN > Destination IP : 192.168.20.2 > Default Services : https (443) > >It doesn't work . It looks like it should work (assuming that the custom service HTTPHIGH is valid for TCP). Have you checked the networking basics? For example: - Is the gateway address of the server at 192.168.20.2 set to the address of IPCop's green port? - Can you ping the server from IPCop? - Is there any possibility that the ISP might be blocking inbound TCP connections to non-standard / any ports? Might be worth trying a quick test with the forwarding rule input service temporarily set to HTTPS (to accept connections on port 443). I am sure that you realise that you cannot test RED->GREEN forwarding from inside of the Green network - you must connect from the Internet side :) HTH, -- Bob Evans -------------------------------------------- Hi Bob, Sorry for the late reply. Yes, I 've checked everything. I tried other services on known ports like ssh from the real world port 22 to inside port 22 and so on. Nothing works. There is something genuinely disturbing about this specific IpCop installation. Oh well. With v1.4.x it was pretty straight forward. Nowadays , I can't get anything to work with v2.x No worries. I am taking it offline in a couple of days and will install a mikrotik router. Thank you very much for your kind reply. Regards, spyros ------------------------------------------------------------------------------ _______________________________________________ IPCop-user mailing list [email protected] Manage your subscription or unsubscribe https://lists.sourceforge.net/lists/listinfo/ipcop-user