• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 408
  • Last Modified:

Help connecting externally to domain

I setup and sbs 2008 domain, but I am having trouble connecting from the outside. I forwarded all the necessary ports. The firewall is a Netgear FVG318 Prosafe. I have configured PIX before, and I know that you have to create access list that says external IP translates to internal IP. EG 66.65.123.45 = 192.168.1.1. Can someone tell me where in the netgear I can do that. I just did some digging around and found this page, (see screenshot). If this is the page, can someone provide an example of a setting.
ScreenShot125.jpg
0
xzay1967
Asked:
xzay1967
  • 10
  • 7
2 Solutions
 
DVation191Commented:
No, you don't want to create a static route.

From the manual:
http://kb.netgear.com/app/answers/detail/a_id/2098
Section 4-6 Port Forwarding

Forward ports in the "Add LAN WAN Inbound Service" section

Or support pages:
http://kbserver.netgear.com/kb_web_files/n101145.asp
http://kb.netgear.com/app/answers/detail/a_id/1166/session/L2F2LzEvc2lkL21ybGNLY3hq

0
 
xzay1967Author Commented:
I had the ports forwarded already. But I think that there has to be somewhere that the router\
firewall has to know what external IP translates to what internal IP, ie 65.65.130.50 would point to 192.168.16.3. Right now the only way I am able to hit from the outside is using the default gateway that ATT gave me. I have block of IP that I was given. I assigned one of the static IP to the server so that users can connect to RWW, or use OWA. I attached a screenshot of my port forwarding setup.
inbound-setup.jpg
0
 
srepphanCommented:
Are you using NAT?
0
Improve Your Query Performance Tuning

In this FREE six-day email course, you'll learn from Janis Griffin, Database Performance Evangelist. She'll teach 12 steps that you can use to optimize your queries as much as possible and see measurable results in your work. Get started today!

 
xzay1967Author Commented:
I thought NAT was used by default. Unless I am missing something, please help me. I think I need to do static routing (Static NAT) so that the internal will know about the external. Am I correct in that assumption? All assistance is appreciated. That is as much I know or don't know. I just need to know if based on the screenshots I provided, if that is enough to accomplish what I need.
0
 
srepphanCommented:
Yes, static NAT is what you want with multiple IPs on the outside interface.
0
 
xzay1967Author Commented:
Can you provide an example please based on the sections from the attached screenshot.
scenario: 95.95.65.130 I want to point to 192.168.16.3 Also, is that the correct place to do the setting?
ScreenShot125.jpg
0
 
srepphanCommented:
I have skimmed the manual and I don't believe that this router supports Static NAT. That usually requires a more feature-rich (read: expensive) router. I AM NOT 100% SURE ON THIS. But most smaller inexpensive routers only support one external IP address. Maybe someone else out there will know more about this particular router/firewall and will be able to provide more insight.

How many IPs did your ISP assign to you? You should have been given a network address (i.e. 64.64.10.136) and a subnet mask (i.e. 255.255.255.248) which would give you 6 IP addresses (i.e. 64.64.10.137-64.64.10.142)
0
 
xzay1967Author Commented:
I was given 5, but only need to use one.
0
 
srepphanCommented:
Well then I don't quite understand what you are trying to do. I thought you wanted to link one external IP to one internal IP. If you just want to link one external IP to multiple internal IPs on different ports, you will use port forwarding.
0
 
xzay1967Author Commented:
you are correct in your assumption about the IP's I got. The subnet mask you assumed, is in fact correct to the very octet. Based on the screen shot I provided, this is not possible to do? I sure wish someone with strong netgear experience would chime in.
0
 
xzay1967Author Commented:
Yes I want to link one external IP to one Internal IP. This is for my SBS 2008 server, so it needs ti handle email: 25, RWW: 987, SSL: 443, VPN: 1723, so I have all the ports forwarded as seen in screen shot.
inbound-setup.jpg
0
 
srepphanCommented:
That looks like that will work.
I checked some other sources and I am told that the Netgear FVG318 will NOT work with more than one external IP.
0
 
xzay1967Author Commented:
Ok, are you saying that setting up the port forwarding is all I need to do? But how does the router know what external IP to translate to what internal IP? Please forgive me questions, I just want this to work. If the router can only do one external IP, then that is ok, because I only want to use one. Right now I can connect to the sever from the server, but only if I use my "Main" external IP, which is actually my broadcast IP. Since that is the case, can I set that IP as the external IP for my mail server when I configure my A and MX records with my site host?
0
 
srepphanCommented:
I get your problem now. You set your routers external IP to be the one IP that you want to communicate with, any other IPs (aside from the broadcast IP) will not be handled by the router. Then you want your MX record to point to that same external IP. But with this configuration, you are wasting the other IP addresses.
0
 
xzay1967Author Commented:
well in the Netgear offers two options to setup your internet, static or ppoe. I chose the option for ppoe because this is with ATT, and they require a username and password.. The netgear then went out and pulled the external IP of 99.56.30.150, but according to the ATT that should be the default gateway. My useable block is 145-150,  My actuall static IP should be 99.56.30.145 as stated by and given to me by ATT. Basically I think the router should have pulled the 145 instead of the 150.
0
 
xzay1967Author Commented:
oops, the usable block is 145-149
0
 
xzay1967Author Commented:
OK, I found out why I am having the issue. I called ATT, and they explained that because I am using the netgear to the authentication, I am going to be able to use one static IP. They explained that I need to move the ppoe back to the 2wire so that it can do the authentication, then I would have my IP issue resolved. Oddly, it was an ATT 2wire specialist that helped me set it up. So now I have to reconfigure the 2wire out of bridge mode. I will keep this open until the weekend, by then all should be gravy. Thanks a lot guys.
0
 
srepphanCommented:
Glad to help, I hope that solves your problem.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Improve Your Query Performance Tuning

In this FREE six-day email course, you'll learn from Janis Griffin, Database Performance Evangelist. She'll teach 12 steps that you can use to optimize your queries as much as possible and see measurable results in your work. Get started today!

  • 10
  • 7
Tackle projects and never again get stuck behind a technical roadblock.
Join Now