Jump to content

Recommended Posts

Posted

Morning all, wondering if someone can help? I've inherited an interesting setup and have Direct Access setup to come in via a BT line and router. Problem is we have no access to the router and the BT line needs to be retired. Our new line has a Ubiquiti firewall and although I have what settings I think should work, DA is not working when redirecting the DNS.

 

Does anyone happen to have a Ubiquiti firewall with Direct Access working that could share their settings?

Posted
Thanks DosBox, I've not had time to get my head round the firewall and we really need to get the BT line cancelled. It's probably something silly like mistranslation by me of terms.
Posted
DA is not working when redirecting the DNS.

 

What do you mean by this? as in trying to redirect port 53 traffic to your dns or?

 

Also which model do you have out of interest?

 

The Edge devices are very good but VyOS is a bit different to use/config.

Posted

Currently DA.ourdomain.org is pointed to our old internet line IPs. With the settings I have in the Ubiquity I changed the DNS to point to new line IP address and it doesn't work. I hadn't seen anything about port 53, so that maybe a large issue.

 

All I can get from the dashboard is EdgeRouter Infinity.

Posted

Is your edgerouter running your external nameserver hosting as well for your domain?

Does https://dnslytics.com/ping show the correct ip?

 

Sorry when I mentioned port 53 I thought it was to do with DA connected clients rather than actually resolving the da.{yourdomain}.org to your new IP.

Posted

I can do the DNS, we have an external DNS provider we can update.

Have no idea of the format of the rules in Ubiquiti. Just to make anything work I have created a firewall policy rule, under WAN IN, accepting all protocols. Then a Source NAT Rule as source of internal DA server and translation to external IP and a Destination NAT Rule as destination external IP and translation as the internal DA server IP.

 

Can't tell if I Am fundamentally doing something wrong or if the Firewall is just not set up right in the first place!

Posted

So yeah Ubiquiti and documentation for VyOS is a bit of a pig. That rule you implied above sounds a bit scary but its maybe more locked down.

I would consider doing a backup using "SYSTEM" at the bottom. The tar.gz file has a config.boot file which mostly has the raw rules being applied if that is easier to read.

WAN_IN is stuff coming in to the firewall going to your internal network, WAN_LOCAL is the traffic going to route only to the edgemax and WAN_OUT is outgoing.

 

There is an old thread: https://community.ui.com/questions/EdgeMax-config-help-needed-for-MS-DirectAccess/bf4c85d8-bb6a-4be0-ba39-5d8fb8a0716e that may offer clues.

I am just wondering if you may be better taking a backup and then using the initial setup wizard to get you back to the start.

Posted

Yeah that rule isn't ideal, but I was hoping to get a ping through or just any traffic to even get to the default IIS server page. Then lock it down.

 

I'll take a look at that thread.

 

Thanks for the pointers

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...