Jump to content

Recommended Posts

Posted

Afternoon everyone.

 

In a bit of a pickle.

 

We have an Untangle firewall and we've lost our "Loopback", i.e. iPads with our public IP or subdomain.domain name can access our site exchange server externally, but not while they are on site. This used to work up until 27-Jan-2015 and the only thing we've done is re-install our untangle server and restore from backup.

 

 

I'm struggling to figure out what we're missing.

 

"Google" and dare I say it "Bing", are not pointing me in the direction I need to go.

 

Thoughts greatly appreciated.

Posted
I can't say I've ever heard of it, but clearly it's a rule issue possibly, seeing as Exchange works outside your LAN and not inside your LAN. Can other devices access your Exchange server internally?
  • Thanks 1
Posted

Cheers for the replies.

 

All our PC clients are configured with internal addresses, however if I browse to our subdomain.domain name to access webmail, it works as expected, prompted to login and I can browse the hoards of emails that seem to accumulate in my inbox, I try deleting them, but they keep on sending them, however that's a different story.

 

So going from this I don't think its an internal DNS issue as we've not changed that, but more a rule issue.

 

I've tried adding in a loopback rule, either I don't understand how I form that rule or I'm barking up the wrong tree.

Posted

I use untangle on our BYOD it is a nice piece of kit, but sometimes it can be a bit clunky.

 

Have your run a report to see if it is being blocked?

 

We put our local domain in the "Pass sites list" it could be as simple as that.

 

It could on the other hand be that your blocking ports on the Firewall section.

 

Or that there was routes setup in your network config.

Posted

Workstations and iPads get them from the same range.

 

Ipads also get the same DNS and gateway settings.

 

Performing a Tracert of the subdomain.domain name on a PC pings back the public IP address (the correct one), not sure how I do that on an iPad (there is bound to be an app for that).

Posted
It doesn't look like a DNS issue or IP related then. The only difference I can see is wired devices vs. wireless, unless I'm missing something obvious! What about using an Android phone or Windows phone connected to your wireless?
Posted

A ping test on untangle:

 

Thu Feb 5 14:16:48 UTC 2015

PING webmail.nineacrespri.iow.sch.UK (213.123.58.139) 56(84) bytes of data.

64 bytes from webmail.nineacrespri.iow.sch.uk (213.123.58.139): icmp_seq=1 ttl=64 time=0.039 ms

64 bytes from webmail.nineacrespri.iow.sch.uk (213.123.58.139): icmp_seq=2 ttl=64 time=0.053 ms

64 bytes from webmail.nineacrespri.iow.sch.uk (213.123.58.139): icmp_seq=3 ttl=64 time=0.068 ms

64 bytes from webmail.nineacrespri.iow.sch.uk (213.123.58.139): icmp_seq=4 ttl=64 time=0.057 ms

64 bytes from webmail.nineacrespri.iow.sch.uk (213.123.58.139): icmp_seq=5 ttl=64 time=0.048 ms

 

--- webmail.nineacrespri.iow.sch.UK ping statistics ---

5 packets transmitted, 5 received, 0% packet loss, time 4000ms

rtt min/avg/max/mdev = 0.039/0.053/0.068/0.009 ms

 

 

DNS Test

 

Thu Feb 5 14:17:41 UTC 2015

webmail.nineacrespri.iow.sch.uk has address 213.123.58.139

Thu Feb 5 14:16:54 GMT 2015 - Test Successful!

 

Tracert

 

Thu Feb 5 14:18:11 UTC 2015

traceroute to webmail.nineacrespri.iow.sch.uk (213.123.58.139), 30 hops max, 40 byte packets

1 webmail.nineacrespri.iow.sch.uk (213.123.58.139) 0.023 ms 0.015 ms 0.015 ms

Thu Feb 5 14:17:24 GMT 2015 - Test Complete!

 

If I add in a DNS entry in untangle pointing webmail.nineacrespri.iow.sch.uk to the local exchange server IP:

 

Thu Feb 5 14:21:33 UTC 2015

webmail.nineacrespri.iow.sch.uk has address 10.141.160.21

Thu Feb 5 14:20:46 GMT 2015 - Test Successful!

 

 

However running a PING test from an iPad, it still refers to the external IP

 

From that I gather the untangle DNS only works if DNS for workstations is hosted by untangle rather than our windows server.

 

So I'm now second guessing myself and thinking it is a local DNS issue or indeed a routing issue on Untangle as you first suggested.

  • 2 months later...
  • 1 month later...
Posted

Okay. Quick update.

Fixed the problem.

Changed the external IP address used in port forwarding to a spare and got the clients to access that. Hey presto it works. So not sure why our original IP address allocation for that service broke, but it's fixed.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...