News: This forum is now permanently frozen.
Pages: [1] 2 3
Topic: Accessing a DSL or cable modem IP from inside the firewall  (Read 18185 times)
« on: August 29, 2008, 16:24:41 »
john99 *
Posts: 44

Hello,

I am trying to aceess my cable modem IP from inside the firewall ( according to http://wiki.m0n0.ch/wikka.php?wakka=AccessingModemOutsideFirewall )
but I does not yet work :-(


Is for that scenario - beside the advanced outbound NAT - as well a (normal) rule required?


Thank's a lot for any help!

John
« Reply #1 on: September 01, 2008, 10:39:23 »
markb ****
Posts: 331

Can you provide some more information about your network setup.  What are the segments? How are you using the DSL modem? Are you passing your external IP through?
« Reply #2 on: September 01, 2008, 11:20:39 »
john99 *
Posts: 44

Thank's markb for the reply!


The IP's of my current network are the followings:

- internal IP of m0n0wall: 192.168.0.7
- machines in my network: 192.168.0.1 / 192.168.0.2 /192.168.0.3 /
- IP of the ZyXel router (that I am trying to access) : 192.168.1.1


According to
http://wiki.m0n0.ch/wikka.php?wakka=AccessingModemOutsideFirewall
I did the following steps:

# 192.168.0.7/exec.php
# ifconfig
# ifconfig vr1 inet 192.168.2/24 alias

see screenshot:


* M0n0_outbound-NAT.jpg (55.77 KB, 589x475 - viewed 769 times.)
« Last Edit: September 02, 2008, 10:14:06 by john99 »
« Reply #3 on: September 02, 2008, 10:02:42 »
thuety *
Posts: 34

There's another solution...

If your monowall has a free OPT interface.. just bridge it with WAN.
So if you need to check your modem just connect to the OPT.

cu, Stefan
« Reply #4 on: September 02, 2008, 10:23:04 »
john99 *
Posts: 44

I failed to answer markb's questions correctly. 2 try...


DSL-modem (ZyXEL P600R-D3):
- Bridge Mode
- DynDNS service/client ( from DynDNS.org )

m0n0wall:
- PPPoE
- outbound NAT ( http://wiki.m0n0.ch/wikka.php?akka=AccessingModemOutsideFirewall )


Thank you very much for any help!

John
« Reply #5 on: September 02, 2008, 10:31:13 »
markb ****
Posts: 331

Glad you added that other post as I was in the middle of typing a reply.
In this case, you need the second half of the document you originally linked to, the part titles "Using PPPoE or PPTP for outside IP address". I have set this up myself and got it working, so hopefully should be able to get it working.

From your second post it looks like you have looked at the first part of the document not the second.  For PPPoE you can skip the static IP part.  If you backed up your config, restore it and try again with the second part.
« Reply #6 on: September 04, 2008, 10:54:05 »
john99 *
Posts: 44

Ok, I created an optional OUT interface (with the WAN interface VR1) with the IP 192.168.2.0 and the 2 advanced Outbound NAT rules (normal LAN NAT and modem NAT)
but it's not yet working (to ping and access the modem behind m0n0wall. Pls see screenshots) ....


- optional Out interface: 192.168.2.0  ( is that IP ok?? )
- internal IP of m0n0wall: 192.168.0.7
- machines in my network: 192.168.0.1 / 192.168.0.2 /192.168.0.3 /
- IP of the ZyXel router (that I am trying to access) : 192.168.1.1


Any additonal help is appreciated very much!

John


* m0n0wall__port-assignement__20080904.gif (2.31 KB, 399x170 - viewed 659 times.)

* m0n0wall__wan-if-opt1.jpg (25.07 KB, 390x419 - viewed 685 times.)

* m3n0wall__NAT--ping-not-working__20080904.jpg (67.56 KB, 750x458 - viewed 694 times.)
« Last Edit: September 05, 2008, 09:14:54 by john99 »
« Reply #7 on: September 05, 2008, 10:16:49 »
john99 *
Posts: 44

Hello,

that are the 2 advanced Outbound NAT rules (normal LAN NAT and modem NAT)
(which I could - due to attachment space limitation - not attach to my last post.

John


* m0n0wall__NAT--modem-NAT__20080905.gif (11.36 KB, 585x437 - viewed 675 times.)

* m0n0wall__NAT--normal-LAN-NAT__20080905.gif (10.66 KB, 579x440 - viewed 696 times.)
« Reply #8 on: September 05, 2008, 10:19:08 »
markb ****
Posts: 331

Hi, no that IP will not work. 192.168.2.0 is a network address and not an IP address.  It also needs to be in the same subnet as your DSL modem.  I would suggest that you change it to 192.168.1.2/24 and try that.
« Reply #9 on: September 08, 2008, 10:33:20 »
john99 *
Posts: 44

Thank you very much markb for you help! Pinging the modem (192.168.1.1) finally works :-)

But accessing the modem with the webbrowser (http://192.168.1.1) not yet... (error message: "Protected Object"). Pls see screenshot.
As I understand, as long as no additional rules are prohibiting http-access to 192.168.1.1, it should work.. Pls see screenshot.

Any idea what I am doing wrong?


Thank you very much!

John




* m2n0wall__192.168.1.1__20080908.jpg (12.26 KB, 370x145 - viewed 649 times.)

* m1n0wall__Rules__LAN__20080908.jpg (16.35 KB, 586x229 - viewed 684 times.)
« Reply #10 on: September 08, 2008, 17:30:51 »
markb ****
Posts: 331

Looking closer at the outbound mapping for the NAT on the OUT interface, I think that the target should be 192.168.1.2 (Your interface IP)  Try this.
« Reply #11 on: September 09, 2008, 11:25:26 »
john99 *
Posts: 44

Now everything is working :-)

Thank you so much markb for your help!


John
« Reply #12 on: September 10, 2008, 10:19:52 »
markb ****
Posts: 331

No problem. Thanks for getting back and letting us know it's sorted.
« Reply #13 on: September 16, 2008, 09:13:20 »
john99 *
Posts: 44

One thing I forgot to ask...

Later on I would like to attach am DMZ on the third port of the ALIX 2C1 board.

Question:
Is it in this case required to add a second opt-interface (in order to be able to access the DSL modem behind m0n0wall from the internal- AND the DMZ-network) ?


Thank's for your help!


John
« Reply #14 on: September 16, 2008, 10:44:15 »
markb ****
Posts: 331

No, you will only have to add additional NAT rules for the DMZ
 
Pages: [1] 2 3
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines