Hi thanks for your help and reply :-)
MattP wrote:This sounds like you have a DNS/NAT error, are your LAN clients able to resolve any domain names from the command line? If WinGate is in a gateway scenario, then we would suggest that you set your LAN clients' default gateway and DNS server settings to point at the WinGate server, this way, DNS resolution requests will work. The exception is if you're running an AD and your AD DNS server is a different machine to the WinGate server, in which case you will point your clients at that machine and then set a forward zone in your AD DNS server. You'll also want to add the IP address of the AD DNS server to the list of DNS servers in Start::Programs::WinGate::Advanced Options to avoid a DNS loop.
Today I check if client can ping internet domain names using
ping
www.mydomain.comand the response is impossible to find host! as you say.. there is a problem with DNS/NAT
So I change the client DNS in the network properties FROM Server IP TO Isp DNS IP and all work!!!!!! Thats great!MattP wrote:It sounds like you don't want to use the WinGate mail services, so you should stop them.
As you say I stop in the System Tab POP3, SMTP, IMAP and in Service Tab POP3 (because I don't want to store mail on server or wingate).
MattP wrote:That sounds like you've created an access restriction policy that is denying access. Can you start off with no policies and verify that connection is ok? If you have created a policy that requires authentication then you must also select some form of authentication from the General tab.
Sorry, I don't know what you are talking about.... I'm new to your program(what's General tab?)
Once installed Wingate I open browser on client and the error message appear.
So I was gone on Service Tab -> WWW Proxy server -> Policies -> and set User can access service + I add "Everyone".
I try again to open browser on client and the error message appear.So I was gone to User Tab - > Assumed User -> and I add Name and IP for my active directory users.
I try again to open browser on client and all works fine! :-)
MattP wrote:For your services, when you say that you set up the proxy (FTP and Telnet) to enable access for two users, did you create a location based policy, or a user based policy? Can you try authenticating with Internet Explorer and then connecting via Telnet on port 23?
Sorry I don't expose well what I did....
When I say " set up the proxy (FTP and Telnet) I mean:
I was gone on Service Tab -> FTP Service (or Telnet) -> Policies -> and set User can access service + I add 2 users.
Now I would like to know if I set correctly Wingate and clients, which is the correct Wingate to buy (I think We need Professional because we use active directory... isn't it?), and I would like to know if I'm behind a proxy or what... this is the config of my lan
Router
Server Win 2000 with 2 ethernet port and Active Directory -> this is the wingate server
Switch
10 client - access to local network with active directory (with SO - win XP, mac osX)
Internet ISP -> Router (cable lan1) -> Server Win 2000 with a Wingate (cable lan 2)-> Switch -> client
I disable in the System Tab POP3, SMTP, IMAP and in Service Tab POP3.
I disable also DNS Service in the System Tab, cause I don't use it.
I set client to access trought the port 80 (HTTP1.1) for all progs/services I need (FTP, TELNET, WWW).
I set email normally, as client are directly connect to internet (POP3, SMTP, IMAP with
www.mydomain.com, user and password etc)
The last questions....
Is there something to do to secure Wingate? Or my actual config it's ok?
If I buy ie. wingate professional can I, after, upgrade to enterprise?
I see you are working on Wingate 7... what about if I want to upgrade from ie: Wingate 6 standard to Wingate 7?
Can we buy from your site or have we to buy from a national reseller?Thanks for all :-)
Cri