Trying to test using 30 dayeval but having trouble with conf

Use this forum to post questions relating to WinGate, feature requests, technical or configuration problems

Moderator: Qbik Staff

Trying to test using 30 dayeval but having trouble with conf

Postby dolfanjm » Oct 05 04 6:28 am

I recently installed wingate on my gateway server which also hosts the companies website. This servers gateway is the ip address of my cisco pix firewall. When i look in the server properties in the bindings tab i see an error in the internal loopback adapter which is the only one listed. The installation instructions are not helpful everything was pretty much installed with default options..... In other words HELP!!

I am evaluating for a 100 user license
dolfanjm
 
Posts: 4
Joined: Oct 05 04 6:20 am

Postby Pascal » Oct 05 04 9:57 am

Bindings on which Service? From the sound of it, and making a bit of a guess, it sounds like the WWW Proxy Service - which will probably conflict with the web-server you are running.

You need to double check that each service (WinGate vs WebServer) are bound only to the adapters necessary as the two cannot bind to the same adapter+port.

Can you post a list of the adapters you have in the machine, though? You should not see only a loopback adapter in the list of bindings.
Pascal

Qbik New Zealand
pascalv@qbik.com
http://www.qbik.com
Pascal
Qbik Staff
 
Posts: 2623
Joined: Sep 08 03 8:19 pm
Location: Auckland, New Zealand

Postby dolfanjm » Oct 05 04 11:15 am

I apologize for not being clear. Yes i am talking about the WWW Proxy Service which is really the only one i am trying to configure as my goal is to control internet access. Now in the server i have 1 adapter with 2 bindings: file and print sharing and client for micorsoft network. Using the gatekeeper to view the WWW Proxy server properties then selecting bindings i see under adapter internal loopback and under binding policy both bind to any and bind to only 127.0.0.1 are checked off. I saved a config file that i can e-mail if possible. thanks
dolfanjm
 
Posts: 4
Joined: Oct 05 04 6:20 am

Postby Pascal » Oct 05 04 11:21 am

First step would be to confirm how many and which adapters (Network cards, modems, etc.) you have in your WinGate Server. All of those should be available as potential targets for binding to.

The second thing to do would be to confirm that the Web Server (IIS, or whatever you are using) and WinGate's WWW Proxy Service are not trying to bind to the same NIC/IP + Port combination.

This is not the TCP/IP properties' bindings, but the actual configuration of the webserver vs WinGate.
Pascal

Qbik New Zealand
pascalv@qbik.com
http://www.qbik.com
Pascal
Qbik Staff
 
Posts: 2623
Joined: Sep 08 03 8:19 pm
Location: Auckland, New Zealand

Postby dolfanjm » Oct 08 04 3:20 am

Pascal i finally got the service to start by binding to the correct adapter and am now using port 8080. I am having trouble with the policy settings i have tried all the options in the config but it will not authenticate maybe im just not understandidng the authentication process i manage my users with Active directory the only service i am trying to use in wingate is WWW proxy Server specifically the ban lists. I have already succesfully synchronized the user database doesn't wingate reference this list as to what user names will authenticate? in other words as soon as i select user must authenticate i get access denied. Is authentication required to use ban lists? Sorry first time user...
dolfanjm
 
Posts: 4
Joined: Oct 05 04 6:20 am

Postby Pascal » Oct 08 04 9:12 am

If you want specific ban lists per users, then you need to authenticate (Or at least assume) the user for WinGate to match up the policy to the connection / user.

As you're using Active Directory, your easiest authentication scheme would be NTLM. I assume you've switched WinGate to use the OS User Database. (Go to the User tab page, change database options). You've probably picked the AD Server as your synchronisation server too, correct?

Now go to the WWW Proxy Service and on the first page, make sure that the NTLM option is checked. Then, go to the policy and set it to "Must be authenticated". Your client browsers should now automatically authenticate using NTLM, for the user currently logged in on that Windows PC.

Have a look at our knowledge base as well, http://support.qbik.com/index.php?_a=knowledgebase, for the articles regarding Active Directory and Authentication.
Pascal

Qbik New Zealand
pascalv@qbik.com
http://www.qbik.com
Pascal
Qbik Staff
 
Posts: 2623
Joined: Sep 08 03 8:19 pm
Location: Auckland, New Zealand


Return to WinGate

Who is online

Users browsing this forum: No registered users and 2 guests

cron