Solved

Web Servers not accessible due to Nat and external DNS

Posted on 2002-04-09
3
320 Views
Last Modified: 2010-04-17
we have a linux machine and an NT webserver which is visible from the outside of the organization thru NAT, using a statememt like:

ip nat inside source static tcp 192.168.1.3 80 213.147.165.130 80 extendable.

browsing the webserver from outside the org. works fine.  However, when we attempt to browse the website from machines from within the org. we get permission dialogs and authentification errors.  This is because essentially, we are trying the browse the router from the inside interface.  Ie, DNS queries for the domain and finds that 213.147.165.130 is the ip address the website is on.  It then tries to connect to this address, but thru the internal router network card.  This causes the login dialog to appear.

Is there a way to tell the router that is should redirect traffic which connects to the external network card via the internal network card on a specific port (i.e. only on port 80, 21 etc) back using the NAT settings?

Thanks

0
Comment
Question by:ossentoo
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 4

Expert Comment

by:svindler
ID: 6927523
You have (at least) three options:
1)
The router will change dns replies if there is a static one-to-one nat ie:
ip nat inside source static 192.168.1.3 213.147.165.130

This is the easiest but require that you actually have a specific ip address to use for each server.
2)
Put the servers on a separate leg of the router, and make the same NAT from inside as from the outside.

This gives you the added benefit of a more secure solution, but is the most expensive.
3)
Setup an internal dns-server with the correct replies for the inside addresses.
This solution can be used in most cases but involves the most work and administrative overhead if you have more servers.
0
 

Author Comment

by:ossentoo
ID: 6931322
I've actually implemented the third solution.  However, if the linux machine which actually hosts the DNS record is switched on first, and then the webserver is switched on after some clients machines have been turned on, the clients get there DNS queries answered by the linux machine, which then informs them that the DNS record for motorsport.co.ug is 213.147.165.130.  

As the webserver is actually at a 192.168.1 address, the client fails and needs to be rebooted in order to get the correct DNS address of 192.168.1.*.  
0
 
LVL 4

Accepted Solution

by:
svindler earned 150 total points
ID: 6932475
What I meant by solution 3 was to setup a dns server on the inside that would actually respond with the 192.168.1.* address of motorsport.co.ug, whenever inside clients asked.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Port forwarding 14 201
Line cards, Supervisor, Control plane 7 67
What problem can Native VLAN mismatch causes 4 80
EIGRP Bandwidth 9 63
In this tutorial I will show you with short command examples how to obtain a packet footprint of all traffic flowing thru your Juniper device running ScreenOS. I do not know the exact firmware requirement, but I think the fprofile command is availab…
The Cisco RV042 router is a popular small network interfacing device that is often used as an internet gateway. Network administrators need to get at the management interface to make settings, change passwords, etc. This access is generally done usi…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

710 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question