Thanks AHoffmann, I have setup 1-1 NAT which has resolved the issue.
Appreciate the help.
Main Topics
Browse All TopicsWe currently have three webservers setup, two of which can only be accessed over https.
We have just recently purchased a Watchguard Firebox x1250e, and I am trying to publish one of our https servers through the 1250, but am not having much luck.
I can access the Internet through the firebox.
I have the firebox connected to the router through the external port.
I have teh firebox connected into the dmz via the trusted port.
I have setup the next port as an optional port and assigned the external IP for our webserver to that port. I then have that port connected into the DMZ.
The webserver can see the firewall (ping) so thats fine, and the webserver is using the firebox as its default gateway (it can access the internet through the firebox)
I have setup a policy to allow HTTPS-Proxy (and this is where I am getting stuck I think):
Do I configure it to allow, for example,:
Any External to Any Optional?
External to Optional?
Optional to Host IP address?
External to Host IP address?
I think I have tried all of these but have not had any joy. I have read through most of the documentation but cannot find the answer. Any help would be great appreciated.
Doris.
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Business Accounts
Answer for Membership
by: ahoffmannPosted on 2009-09-05 at 23:20:02ID: 25268876
you have to configure NAT
Any connectuon (port 80,443) on the external interface needs to be proxied to the web server's IP in the DMZ which means that the firewall needs to rewrite the destination IP (from your external public IP to your internal DMZ IP). If it is a statefull inspection firewall, that's all. Otherwise you need to make another NAT rule the other way around.