Switch to full style
Use this forum to post questions relating to WinGate, feature requests, technical or configuration problems
Post a reply

Allowing an external IP address access through the firewall

Mar 19 04 5:16 am

I have a strange request and i really am struggling on this!

I need to allow a specific external / public IP address (which is a mail server in a DMZ Area of out network) full access through the WinGate firewall so it can see one of our internal / private servers.

I cannot see any way of allowing this in the software - is it possible???

Mar 19 04 9:14 am

Hi there

By access to the Internal server do you mean in a LAN sense (drive shares, files etc) or a Application sense, ie The server is running an application like a webserver or similar that is accessed from the Internet.

If it is in a LAN sense then that is what WinGate VPN is designed to allow you to do in a secure environment. Or alternatively you can look at the help section on creating a TCP mapping to see if it suites your needs.

If it is in Application sense the you can redirect inbound traffic to a specific internal server through the port security tab in the ENS config of WinGate obviously configuring the correct ports required.

Regards
Erwin

Mar 19 04 10:19 pm

Hi thanks for the reply, note sure what you mean tho, i shall explain further.

We have a dedicated internet conection that comes into a hub.

Into this is plugged our DMZ "webmail" server and also in the same hub is a connection to another server running the firewall software (which in turn connects via a second network card to our LAN), this is where all normal internet traffic goes through.

What i want to be able to do is allow our DMZ "webmail" server to have full access through the firewall to the internal LAN to access other email servers.

Hope this makes a bit more sense!!!

Mar 26 04 1:14 am

This is also now fixed with help from the QBik support team!

FYI here is what i needed to do

- Setup an "Assumed User" with the IP address of the external DMZ server and tell it is was automatically assuming to be the admin.
- Setup / Changed a Port for the communications to allow the DMZ server to come in on and restrict access to this port to the assumed user only
- Setup a mapping in the Above Port config to go to the specific email server i wanted it to go to.

It is now all working perfectly!
Post a reply