neonetman Posted November 26, 2019 Posted November 26, 2019 Good morning all... I've got a really strange issue with incoming traffic to our web-facing servers. We run Smoothwall as a firewall, and need to access our RD Gateway server and a number of websites hosted internally. I have allocated 2 IP addresses for incoming traffic - one has a firewall rule and port forward direct to our RD Gateway server. The other has identical firewall and port forwards to our Kemp Loadmaster (used as a reverse proxy) This is the issue I'm having:- Mobile Hotspot -> Smoothwall -> RD Gateway [WORKS] Home Wifi -> Smoothwall -> RD Gateway [WORKS] Mobile Hotspot -> Smoothwall -> Kemp [WORKS] Home Wifi -> Smoothwall -> Kemp [DOESN'T WORK] There is no filtering on my home WiFi to get in the way, and I have also tried swapping the port forwards between Kemp and RD Gateway - so I know the firewall rules are correct. It seems that it is some external connections will connect to Kemp, but not others I'm at a bit of a loss what to try next (wondering if MTU has anything to do with it, but not sure where/which device to change for that) 1
neonetman Posted November 27, 2019 Author Posted November 27, 2019 Has no-one any thoughts at all on this? I'm tearing my hair out (what little of it there is left)
MartinT Posted November 27, 2019 Posted November 27, 2019 I'm not entirely clear on why you are mixing port forwards with reverse proxy. Are you using Smoothwall's reverse proxy, and is your external address of the form... https://remote.domain/rdweb ...leading to the IP address of the RD gateway server?
neonetman Posted November 27, 2019 Author Posted November 27, 2019 The reverse proxy on the smoothwall is very flaky, and doesn't allow for certificate re-encryption, login interfaces etc (all of which we used on our outgoing TMG box). The aim is to have 1 IP address (and URL) be prot forwarded to our RD Gateway server directly The remaining URL''s would point to the the 2nd external IP, which is port-forwarded to our Kemp Loadmaster internally. This will provide the necessary facilities that Smoothwall RP does not provide. If there is a better way of doing this, then please tell me - I'm after the simplest option ot make everything work
MartinT Posted November 27, 2019 Posted November 27, 2019 Ah I see, we use Smoothwall's reverse proxy for e-mail, RemoteApp, Firefly, LANsweeper etc. and it all works very reliably. I use RD a lot at home for sorting things out remotely. You do need a wildcard certificate, ideally, for allowing all these https services through.
ibpalle Posted November 28, 2019 Posted November 28, 2019 The setup sound correct - 2 port forwards on different IPs and they are both working fine. No need to change that I think. The problem could be routing - I am assuming the Kemp load balancer is using the Smoothwall as it's default gateway out of the network - do you have any SNAT rues in place for the IPs "behind" your port forward?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now