Link to home
Start Free TrialLog in
Avatar of xzay1967
xzay1967

asked on

Help connecting externally to domain

I setup and sbs 2008 domain, but I am having trouble connecting from the outside. I forwarded all the necessary ports. The firewall is a Netgear FVG318 Prosafe. I have configured PIX before, and I know that you have to create access list that says external IP translates to internal IP. EG 66.65.123.45 = 192.168.1.1. Can someone tell me where in the netgear I can do that. I just did some digging around and found this page, (see screenshot). If this is the page, can someone provide an example of a setting.
ScreenShot125.jpg
SOLUTION
Avatar of DVation191
DVation191

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of xzay1967
xzay1967

ASKER

I had the ports forwarded already. But I think that there has to be somewhere that the router\
firewall has to know what external IP translates to what internal IP, ie 65.65.130.50 would point to 192.168.16.3. Right now the only way I am able to hit from the outside is using the default gateway that ATT gave me. I have block of IP that I was given. I assigned one of the static IP to the server so that users can connect to RWW, or use OWA. I attached a screenshot of my port forwarding setup.
inbound-setup.jpg
Are you using NAT?
I thought NAT was used by default. Unless I am missing something, please help me. I think I need to do static routing (Static NAT) so that the internal will know about the external. Am I correct in that assumption? All assistance is appreciated. That is as much I know or don't know. I just need to know if based on the screenshots I provided, if that is enough to accomplish what I need.
Yes, static NAT is what you want with multiple IPs on the outside interface.
Can you provide an example please based on the sections from the attached screenshot.
scenario: 95.95.65.130 I want to point to 192.168.16.3 Also, is that the correct place to do the setting?
ScreenShot125.jpg
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
I was given 5, but only need to use one.
Well then I don't quite understand what you are trying to do. I thought you wanted to link one external IP to one internal IP. If you just want to link one external IP to multiple internal IPs on different ports, you will use port forwarding.
you are correct in your assumption about the IP's I got. The subnet mask you assumed, is in fact correct to the very octet. Based on the screen shot I provided, this is not possible to do? I sure wish someone with strong netgear experience would chime in.
Yes I want to link one external IP to one Internal IP. This is for my SBS 2008 server, so it needs ti handle email: 25, RWW: 987, SSL: 443, VPN: 1723, so I have all the ports forwarded as seen in screen shot.
inbound-setup.jpg
That looks like that will work.
I checked some other sources and I am told that the Netgear FVG318 will NOT work with more than one external IP.
Ok, are you saying that setting up the port forwarding is all I need to do? But how does the router know what external IP to translate to what internal IP? Please forgive me questions, I just want this to work. If the router can only do one external IP, then that is ok, because I only want to use one. Right now I can connect to the sever from the server, but only if I use my "Main" external IP, which is actually my broadcast IP. Since that is the case, can I set that IP as the external IP for my mail server when I configure my A and MX records with my site host?
I get your problem now. You set your routers external IP to be the one IP that you want to communicate with, any other IPs (aside from the broadcast IP) will not be handled by the router. Then you want your MX record to point to that same external IP. But with this configuration, you are wasting the other IP addresses.
well in the Netgear offers two options to setup your internet, static or ppoe. I chose the option for ppoe because this is with ATT, and they require a username and password.. The netgear then went out and pulled the external IP of 99.56.30.150, but according to the ATT that should be the default gateway. My useable block is 145-150,  My actuall static IP should be 99.56.30.145 as stated by and given to me by ATT. Basically I think the router should have pulled the 145 instead of the 150.
oops, the usable block is 145-149
OK, I found out why I am having the issue. I called ATT, and they explained that because I am using the netgear to the authentication, I am going to be able to use one static IP. They explained that I need to move the ppoe back to the 2wire so that it can do the authentication, then I would have my IP issue resolved. Oddly, it was an ATT 2wire specialist that helped me set it up. So now I have to reconfigure the 2wire out of bridge mode. I will keep this open until the weekend, by then all should be gravy. Thanks a lot guys.
Glad to help, I hope that solves your problem.