Solved

Cannot tracert external IP of my firewall.

Posted on 2007-11-18
8
2,098 Views
Last Modified: 2013-12-19
I just installed a secondhand Watchguard Firebox SOHO 6tc and have been working to set it up.  At this time, I am comfortable with setting allowances/restrictions on incoming and outgoing traffic with one exception.  I cannot communicate with my external IP address.  For example, if I set up an FTP server in my network and make the appropriate allowances, people outside of my network can use my FTP server.  I, on the other hand, cannot.  For some reason, I can't communicate with my external IP address while others can.  They are only restricted by my incoming permissions where I can't figure out how to allow myself access to anything.  If I tracert my external IP, it starts timing out as soon as it gets to the point where it would be going through my firewall.  (My firewall never shows up in the tracert if I try my external IP)  If I tracert another IP (such as google), my firewall shows up right before the trace hits my ISP.  Any ideas?  
0
Comment
Question by:Petra_fan1
  • 4
  • 3
8 Comments
 
LVL 37

Expert Comment

by:Bing CISM / CISSP
ID: 20311748
> For some reason, I can't communicate with my external IP address while others can.

from external side or internal?
0
 
LVL 32

Expert Comment

by:dpk_wal
ID: 20313362
I am not sure about the tracert it should work, check with your ISP if they are blocking anything, for the FTP or any other server hosted behind WG SOHO6tc, I think the problem you have is, others can communicate with FTP using the public IP but you are not able to do so with the external or public IP; you would be needed to use internal or private IP instead.
If you have domain setup then you should either configure a setting in the hosts file [%windir%/system32/drivers/etc/hosts] which would translate your domain to the internal IP address or if you have a internal DNS Server configure it as caching server for domain which would redirect all internal request to the internal IP.

Please let know if I am able to answer your question.

Thank you,
0
 

Author Comment

by:Petra_fan1
ID: 20590926
Alright, for clarification:
From inside of my network, if I type my external IP address (or DNS name I registered to my public IP) into my browser, I get nothing.  The page times out.
From outside of my network, if I type my external IP address (or DNS name I registered to my public IP) into my browser, I get my website.
In both cases, if I ping my DNS name, it resolves to my external IP address, so I know its not an issue with DNS in my network.

Before using this Firebox, I had a router in the same position of the network, and everything worked fine.  With this said, I thought it might be something I'm blocking with my firewall configuration, but if it was, than I shouldn't be able to access other websites from inside of my network or my website from outside of my network, right?

Any thoughts?  Thanks for the help.
0
 
LVL 32

Accepted Solution

by:
dpk_wal earned 250 total points
ID: 20592563
Let me explain what is happening:

With most of the networking devices, ingress interface cannot be same as the egress interface.

Now when you use external IP or DNS name the packets go out of SOHO and would come back on the same interface which is not supported. Few vendors, like Cisco implement something called hairpin for such connections; however, WG does not implement hairpin.

So, the solution is to have the internal machines do not send request out but rather query the internal server; so you can modify the hosts file on the individual machines or if you have an internal DNS caching server you can have it redirect all the request for DNS name to the internal IP.
With external  IP of the website it would not work behind WG at all.

Please let know if you need more details.

Thank you.
0
What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

 

Author Comment

by:Petra_fan1
ID: 20592580
That is the answer I was looking for.  Unfortunately, its not the answer I wanted, but it makes perfect sense when put that way.  I have modified my internal DNS system accordingly but have been running into some difficulty due to port/name relations where a firewall/router can specify ports and then the internal device recognizes names...But I'm working towards a solution with a reverse transparent proxy that I am trying to implement.  If I am correct, that should give me a solution I'll be happier with.  Thank you for your time.
0
 

Author Closing Comment

by:Petra_fan1
ID: 31409845
Thank you very much.  You explained that very well.
0
 
LVL 32

Expert Comment

by:dpk_wal
ID: 20592599
You are welcome. The proxy might help, but am not 100% sure; because if proxy would also query on the public IP then same thing would happen.

Thank you.
0
 

Author Comment

by:Petra_fan1
ID: 20592632
That's why my aim is to use that in conjunction with my internal DNS so all computers will be oblivious to the rerouting (which is why I am thinking of the transparent option).  Its kind of a hack idea, but I think it will work nicely when properly implemented.  It is a small enough network that it shouldn't be a problem (I hope.  LOL).  
0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
This is the first one of a series of articles I’ll be writing to address technical issues that are always referred to as network problems. The network boundaries have changed, therefore having an understanding of how each piece in the network  puzzl…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now