Solved

Cannot tracert external IP of my firewall.

Posted on 2007-11-18
8
2,171 Views
Last Modified: 2013-12-19
I just installed a secondhand Watchguard Firebox SOHO 6tc and have been working to set it up.  At this time, I am comfortable with setting allowances/restrictions on incoming and outgoing traffic with one exception.  I cannot communicate with my external IP address.  For example, if I set up an FTP server in my network and make the appropriate allowances, people outside of my network can use my FTP server.  I, on the other hand, cannot.  For some reason, I can't communicate with my external IP address while others can.  They are only restricted by my incoming permissions where I can't figure out how to allow myself access to anything.  If I tracert my external IP, it starts timing out as soon as it gets to the point where it would be going through my firewall.  (My firewall never shows up in the tracert if I try my external IP)  If I tracert another IP (such as google), my firewall shows up right before the trace hits my ISP.  Any ideas?  
0
Comment
Question by:Petra_fan1
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
8 Comments
 
LVL 37

Expert Comment

by:bbao
ID: 20311748
> For some reason, I can't communicate with my external IP address while others can.

from external side or internal?
0
 
LVL 32

Expert Comment

by:dpk_wal
ID: 20313362
I am not sure about the tracert it should work, check with your ISP if they are blocking anything, for the FTP or any other server hosted behind WG SOHO6tc, I think the problem you have is, others can communicate with FTP using the public IP but you are not able to do so with the external or public IP; you would be needed to use internal or private IP instead.
If you have domain setup then you should either configure a setting in the hosts file [%windir%/system32/drivers/etc/hosts] which would translate your domain to the internal IP address or if you have a internal DNS Server configure it as caching server for domain which would redirect all internal request to the internal IP.

Please let know if I am able to answer your question.

Thank you,
0
 

Author Comment

by:Petra_fan1
ID: 20590926
Alright, for clarification:
From inside of my network, if I type my external IP address (or DNS name I registered to my public IP) into my browser, I get nothing.  The page times out.
From outside of my network, if I type my external IP address (or DNS name I registered to my public IP) into my browser, I get my website.
In both cases, if I ping my DNS name, it resolves to my external IP address, so I know its not an issue with DNS in my network.

Before using this Firebox, I had a router in the same position of the network, and everything worked fine.  With this said, I thought it might be something I'm blocking with my firewall configuration, but if it was, than I shouldn't be able to access other websites from inside of my network or my website from outside of my network, right?

Any thoughts?  Thanks for the help.
0
What, When and Where - Security Threats from Q1

Join Corey Nachreiner, CTO, and Marc Laliberte, Information Security Threat Analyst, on July 26th as they explore their key findings from the first quarter of 2017.

 
LVL 32

Accepted Solution

by:
dpk_wal earned 250 total points
ID: 20592563
Let me explain what is happening:

With most of the networking devices, ingress interface cannot be same as the egress interface.

Now when you use external IP or DNS name the packets go out of SOHO and would come back on the same interface which is not supported. Few vendors, like Cisco implement something called hairpin for such connections; however, WG does not implement hairpin.

So, the solution is to have the internal machines do not send request out but rather query the internal server; so you can modify the hosts file on the individual machines or if you have an internal DNS caching server you can have it redirect all the request for DNS name to the internal IP.
With external  IP of the website it would not work behind WG at all.

Please let know if you need more details.

Thank you.
0
 

Author Comment

by:Petra_fan1
ID: 20592580
That is the answer I was looking for.  Unfortunately, its not the answer I wanted, but it makes perfect sense when put that way.  I have modified my internal DNS system accordingly but have been running into some difficulty due to port/name relations where a firewall/router can specify ports and then the internal device recognizes names...But I'm working towards a solution with a reverse transparent proxy that I am trying to implement.  If I am correct, that should give me a solution I'll be happier with.  Thank you for your time.
0
 

Author Closing Comment

by:Petra_fan1
ID: 31409845
Thank you very much.  You explained that very well.
0
 
LVL 32

Expert Comment

by:dpk_wal
ID: 20592599
You are welcome. The proxy might help, but am not 100% sure; because if proxy would also query on the public IP then same thing would happen.

Thank you.
0
 

Author Comment

by:Petra_fan1
ID: 20592632
That's why my aim is to use that in conjunction with my internal DNS so all computers will be oblivious to the rerouting (which is why I am thinking of the transparent option).  Its kind of a hack idea, but I think it will work nicely when properly implemented.  It is a small enough network that it shouldn't be a problem (I hope.  LOL).  
0

Featured Post

Free Backup Tool for VMware and Hyper-V

Restore full virtual machine or individual guest files from 19 common file systems directly from the backup file. Schedule VM backups with PowerShell scripts. Set desired time, lean back and let the script to notify you via email upon completion.  

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Many of us in IT utilize a combination of roaming profiles and folder redirection to ensure user information carries over from one workstation to another; in my environment, it was to enable virtualization without needing a separate desktop for each…
Are you one of those front-line IT Service Desk staff fielding calls, replying to emails, all-the-while working to resolve end-user technological nightmares? I am! That's why I have put together this brief overview of tools and techniques I use in o…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
Suggested Courses

626 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question