News: This forum is now permanently frozen.
Pages: [1]
Topic: NAT/FW-rules: Forwarding all HTTP to Lan IP  (Read 3129 times)
« on: March 07, 2008, 08:35:57 »
priorismono *
Posts: 11

Hi, all

Finally changing form my old D-link router/fw to a monowall PC.
Most of it works great either in 1.233 or 1.3b10. However, I seem not to be able to do as I used to do with my old D-link. (NAT)  Huh

I have dynamic IPs and did setup a DynDNS with No-IP.com. (Wan IP gets updated with Linux box, and works) To avoid issues with ISP I do a port redirect to port 99. (No-ip does that for free)

My Linux server is listening to port 80 on my LAN.  So I want to redirect all incoming HTTP on port 99 to internal IP on port 80. How do I do this?  I've tried all possible settings (mimic from D-link settings too because it works there) and not luck.  Cry  Even if I skip the port redirect for testing purposes I can't get to my server. Strangely though I get the monowall GUI interface on my wan-IP at port 80. Don’t like that actually.
Any hints on how to set this up correctly?

Greatly appreciated
M.S.
« Reply #1 on: March 07, 2008, 09:18:09 »
ChainSaw
Guest

NAT Rule:   |   WAN   |   TCP   |   99   |   {IP or better yet Alias of your web server}   |   80   |

WAN Rule:  |   TCP   |   *   |   *   |   {IP or better yet Alias of your web server}   |   80   |

CS...
« Last Edit: March 07, 2008, 09:21:28 by ChainSaw »
« Reply #2 on: March 07, 2008, 09:55:11 »
priorismono *
Posts: 11

That's exactly the rules I have, but not working.

mono gui is still coming up on wan at port 80
on port 99, nothing. can't get to server.

??hints?? (same thing on boht versions 1.233 or 1.3b10
« Reply #3 on: March 07, 2008, 17:29:17 »
ChainSaw
Guest

reset your m0n0wall to Factory Defaults and try those rules again.  If you still have a problem post more details on your setup.

CS...
« Reply #4 on: March 07, 2008, 19:42:11 »
priorismono *
Posts: 11

Ok complete rundown on a test I did:

First Network setup: IPS >> DSL-Modem >> MONOWALL-WAN >>MONOWALL-LAN >> Switch >> PC’s


  • Create new CF with 1.3b10
  • Setup all NIC correctly with console
  • Use default settings for lan (192.168.1.1)
  • Acquire local IP for my notebook (Lan)
  • Open IE7, type local address 192.168.1.1: webGui opens.
  • Browse in WebGui to system/interface to gather new WAN IP
  • Open new IE7 (kill all cash files and history) type WAN IP and enter:  Again the WebGui opens with request for user and password, and let me in.
  • Disconnect power to DSL-modem
  • Open new IE7 (kill all cash files and history) type WAN IP from before in and: Again the WebGui pops up with request for user and password, and let me in. 


So Mono must make a link from behind the FW on the local IP’s to the WAN IP and notice I’m a local user and reroute me to the local IP of mono again. HOW COME?

That might explain why even with setup NAT forwarding and FW rules to have HTTP  to be rerouted on LAN server I always get the WebGui.

What do I do wrong?



Second test, with this new setup (factory defaults) I added the rules as suggested. but no success.


Thanks in advance. 
« Last Edit: March 07, 2008, 19:59:27 by priorismono »
« Reply #5 on: March 07, 2008, 20:47:55 »
ChainSaw
Guest

m0n0wall does not allow that type of loopback connection.  have you tested it from another remote internet connection?

CS...
« Reply #6 on: March 08, 2008, 01:51:05 »
priorismono *
Posts: 11

Tried different setup now,

Wan
Lan
DMZ

followed this step by step http://doc.m0n0.ch/handbook/examples.html#id2603650

Still get the same thing that my http is not forwarded and that if I from behind the mono, the external ip type in the browser the webGui pops up.

Have done it soo many times with Dlink or linksys routers,  and eventhough mono seems to be all strait forward, it wont work.

do I need to forward xml file? (in attachment as txt )

could it be my hard ware that is causing this? I'm using an old DEC

Help help. Thanks.

* config-m0n0wall.local-20080308003359.txt (4.31 KB - downloaded 198 times.)
« Reply #7 on: March 08, 2008, 05:44:13 »
ChainSaw
Guest


http://doc.m0n0.ch/handbook/faq-lannat.html

CS...
« Reply #8 on: March 09, 2008, 00:29:24 »
priorismono *
Posts: 11

Thanks man, I appreciate it.
While thinking I had a problem it seemed all to be working (not as stable as I would like it to be but hey what can I say, using the beta version.) once I've added the loop for the home domain to the DMZ, it seems to work behind the FW too. Outside, I never tested as I assumed it would be the same from behind the FW as it is with Dlink routers.  Having access to few open hot spots I tried it from the outside and hey all working fine. I guess now its about fine tuning, and maybe upgrading my old DEC hard ware a bit. LOL 

Have a nice weekend. (Case closed)
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines