I can't make the client connect to wingate server...

Use this forum to post questions relating to WinGate, feature requests, technical or configuration problems

Moderator: Qbik Staff

I can't make the client connect to wingate server...

Postby digaumsmile » Dec 18 07 8:29 am

Hi everyone...

I have installed wingate at my office... to block internet to employes.

My modem is set as "router"... I made the ping test and it worked fine.

I've got 10 pcs here, but my boss wants to block internet only in 5 pcs. I have two ethernet adapters installed (I'm the server) , both plugged in a HUB. The first adapter, has the ip number 10.0.0.1, mask 255.255.255.0, gateway 10.0.0.138 and DNS 200.204.0.10/200.204.0.138. The second has ip 192.168.0.1, mask 255.255.0.0 and gateway 10.0.0.1. Is that right???

Thanks so far.

Rodrigo
digaumsmile
 
Posts: 3
Joined: Dec 18 07 7:39 am

Re: I can't make the client connect to wingate server...

Postby Nev » Dec 18 07 10:13 pm

digaumsmile wrote: The second has ip 192.168.0.1, mask 255.255.0.0 and gateway 10.0.0.1. Is that right??? Thanks so far.

Rodrigo


Hi Rodrigo,

In Gatekeeper check in the Network tab that the Class C NIC is marked as Internal and the other to the router is external.

This internal NIC 192.168.0.1 should only have a mask and NO gateway at all.

What you could do to allow only 5 clients access is easy if they have a static IP.

If they are to have full access you can ban the others.

What I do is to create a System Policy and add the IP addresses of the clients who are NOT to have any access.

It looks like this example for one client address:

Image

Next in any service you want to block open the Policies and set them to 'System Policies Must Also Be Granted' for this to work, for example the WWW proxy and ENS then web browsing will cease for every client in the list.

Or, you can create a policy like this for each service to ban a user IP too, I just happen to like System policies.
--
Nev.
Nev
WinGate Guru
 
Posts: 861
Joined: Sep 22 03 11:35 pm
Location: Mudgee ~ NSW ~ Australia

Postby digaumsmile » Dec 19 07 7:41 am

okay... i undestood..

Both are set as "Internal"...

I don't want to receive all internet at all. My bosses pcs will not be proxy clients... they will receive it freely.

When I meant "I'm the server" I was wrong...lol... I'll be the server only to block the employees pcs...

is that possible to do something like this behind:

------------------------------------------------------------------
internet --> router --> HUB |--> boss #1
----------------------------------|--> boss #2
----------------------------------|--> my pc --> employee #1
--------------------------------------------|--> employee #2
--------------------------------------------|--> employee #3
--------------------------------------------|--> employee #4
--------------------------------------------|--> employee #5
------------------------------------------------------------------

'Cause my bosses arrive here first than the employees, they turn on the modem, hub and pc and surf freely in the internet, got it?

Thanks so far

Rodrigo
    digaumsmile
     
    Posts: 3
    Joined: Dec 18 07 7:39 am

    Postby Nev » Dec 19 07 3:13 pm

    digaumsmile wrote:Both are set as "Internal"...


    Ok, you should set the NIC on the Class A // 10.0.0.1 as 'External' and if you want to use the proxy for your services, just set your Internet Options to the localhost // 127.0.0.1:80 for example.

    Next you could stop the client pc's with a Filter // Criterion where rights are not met if their IP contains part of their IP address should work.
    --
    Nev.
    Nev
    WinGate Guru
     
    Posts: 861
    Joined: Sep 22 03 11:35 pm
    Location: Mudgee ~ NSW ~ Australia

    Postby digaumsmile » Dec 20 07 5:20 am

    I had set both of adapters, as you said, but i still couldn't connect the client to the server.

    Client is set this way:

    IP: 192.168.0.2
    subnet mask: 255.255.0.0
    gateway: 192.168.0.1
    DNS: blank

    Is this right??

    Thanks

    Rodrigo
    digaumsmile
     
    Posts: 3
    Joined: Dec 18 07 7:39 am

    Postby Nev » Dec 20 07 4:36 pm

    digaumsmile wrote:I had set both of adapters, as you said, but i still couldn't connect the client to the server.

    Client is set this way:

    IP: 192.168.0.2
    subnet mask: 255.255.0.0
    gateway: 192.168.0.1
    DNS: blank

    Is this right??

    Thanks

    Rodrigo


    Hi Rodrigo,

    What you need there is to have the DNS requests forwarded to Wingate so the Client configuration would be:

    IP: 192.168.0.2
    Mask: 255.255.255.0
    Gateway: 192.168.0.1
    DNS: 192.168.0.1

    That way name resolution will go from the client via Wingate.

    Lastly, ping the Server from a client // CMD // ping 192.168.0.1 for four replies must be ok.

    Also, you can ping an Internet host to verify that the client has DNS access // CMD // ping ato.gov.au for four replies.
    --
    Nev.
    Nev
    WinGate Guru
     
    Posts: 861
    Joined: Sep 22 03 11:35 pm
    Location: Mudgee ~ NSW ~ Australia


    Return to WinGate

    Who is online

    Users browsing this forum: Bing [Bot] and 17 guests

    cron