Jump to content

Recommended Posts

Posted

Good morning all... I've got a really strange issue with incoming traffic to our web-facing servers.

 

We run Smoothwall as a firewall, and need to access our RD Gateway server and a number of websites hosted internally.

 

I have allocated 2 IP addresses for incoming traffic - one has a firewall rule and port forward direct to our RD Gateway server. The other has identical firewall and port forwards to our Kemp Loadmaster (used as a reverse proxy)

 

This is the issue I'm having:-

 

Mobile Hotspot -> Smoothwall -> RD Gateway [WORKS]

Home Wifi -> Smoothwall -> RD Gateway [WORKS]

 

 

Mobile Hotspot -> Smoothwall -> Kemp [WORKS]

Home Wifi -> Smoothwall -> Kemp [DOESN'T WORK]

 

There is no filtering on my home WiFi to get in the way, and I have also tried swapping the port forwards between Kemp and RD Gateway - so I know the firewall rules are correct.

 

It seems that it is some external connections will connect to Kemp, but not others

 

I'm at a bit of a loss what to try next (wondering if MTU has anything to do with it, but not sure where/which device to change for that)

  • Thanks 1
Posted

The reverse proxy on the smoothwall is very flaky, and doesn't allow for certificate re-encryption, login interfaces etc (all of which we used on our outgoing TMG box).

 

The aim is to have 1 IP address (and URL) be prot forwarded to our RD Gateway server directly

 

The remaining URL''s would point to the the 2nd external IP, which is port-forwarded to our Kemp Loadmaster internally. This will provide the necessary facilities that Smoothwall RP does not provide.

 

If there is a better way of doing this, then please tell me - I'm after the simplest option ot make everything work

Posted

Ah I see, we use Smoothwall's reverse proxy for e-mail, RemoteApp, Firefly, LANsweeper etc. and it all works very reliably.

 

I use RD a lot at home for sorting things out remotely.

 

You do need a wildcard certificate, ideally, for allowing all these https services through.

Posted
The setup sound correct - 2 port forwards on different IPs and they are both working fine. No need to change that I think. The problem could be routing - I am assuming the Kemp load balancer is using the Smoothwall as it's default gateway out of the network - do you have any SNAT rues in place for the IPs "behind" your port forward?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...