Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

SMC Comcast Business Router Configuration

Posted on 2009-06-29
9
Medium Priority
?
2,491 Views
Last Modified: 2013-12-14
There are a number of other posts with similar questions, but none that I found were able to help me.

When you get a business line from Comcast they give you an SMC router/firewall/modem. Before switching to Comcast business, we had a SonicWall firewall configured and working perfectly for our previous ISP. It allowed inbound terminal services to our terminal services server and OWA (http/https) connections to our exchange server.

Now that I have to place this SMC router in front of the firewall, I'm in a situation where getting the double NAT'ed firewalls working is not as simple as I had hoped.

I know the setup below is wrong because although I have internet access from behind the SonicWall, I can't get in from the outside using services that previously worked (OWA and terminal services).

Comcast wrote down two IPs on the work order:
IP#1: 173.xxx.xxx.205/24
IP#2: 173.xxx.xxx.206/30
Gateway: 10.1.10.1

So this is my setup on the SonicWall:
WAN: NAT-Enabled Static IP: 173.xxx.xxx.205/24
Gateway: 10.1.10.1

SMC:
LAN IP: 10.1.10.1/24
WAN IP: 173.xxx.xxx.206

Static IP Block 173.xxx.xxx.206/30
"Firewall for True Static IP Subnet Only" disabled
"Gateway Smart Packet Detection" disabled
"Static Routing" disabled
"Port Forwarding" disabled
"1 to 1 NAT" disabled
173.xxx.xxx.205 is in the DMZ (I was trying to achieve a "bridge-like" mode even though this device doesn't have a bridge mode)

When I check my public IP from behind the SonicWall, it's currently 173.xxx.xxx.205

What do I need to change for this to work properly?

0
Comment
Question by:DVation191
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
  • 2
9 Comments
 
LVL 32

Accepted Solution

by:
nappy_d earned 2000 total points
ID: 24744412
Did Comcast provide you with any public IPs for usage?

Does the SMC device have any ethernet ports on it?  If so, try configuring your sonicwall with one of the public IPs and connect it to the LAN port on the SMC box.
0
 
LVL 20

Author Comment

by:DVation191
ID: 24744555
Well the smc gateway has an ip of .206, I;m supposed to be using the .205 address, as we've paid for a static IP.

The SMC does have ethernet ports on it - 4 to be exact. If I configure the SonicWall's WAN IP as the .205 IP, what do I use as the gateway?
0
 
LVL 32

Expert Comment

by:nappy_d
ID: 24744616
Use the .206 as the gateway.  This gateway is not for the SMC device but your ISP's gateway for the internet.

Connect your Sonicwall unit to the etheret port located on the SMC device.
0
Create the perfect environment for any meeting

You might have a modern environment with all sorts of high-tech equipment, but what makes it worthwhile is how you seamlessly bring together the presentation with audio, video and lighting. The ATEN Control System provides integrated control and system automation.

 
LVL 20

Author Closing Comment

by:DVation191
ID: 31597886
Thank you!
0
 
LVL 11

Expert Comment

by:emilgas
ID: 24747379
One major Issue:
The part that your sonicWall has a WAN ip of 173.xxx and a Gateway of 10.1.10.1 is wrong. You can never have that. Meaning the Gateway and IP of the device have to be on the same network.
Issue Number 2: you mentioned that:
173.xxx.xxx.205 is in the DMZ (I was trying to achieve a "bridge-like" mode even though this device doesn't have a bridge mode) and 1 to 1 NAT" disabled
So what is your internal IP address of sonic wall? How does it communicate with the gateway you provided? Like I said they have to be on the same network for them to talk to each other. there needs to be some sort of a translation or NATing. (your issue number 2)
I just gave you list of things that are wrong but I have not provided any solution. So answer these questions so I can give you some more help. Which device acts as the DHCP server? Which device does the NATing? May be you can disable the NAT on your SMC device and make it act like a layer 2 bridge (roughly).
Let me know
0
 
LVL 20

Author Comment

by:DVation191
ID: 24747414
Setting the WAN IP on the firewall to .205 and using .206 as the gateway (the smc device), I was able to get an internet connection working with .205 as my public IP. My internal addresses behind the firewall are using 192.168.40.x, but that doesn't seem relevant. Everything seems to be working now.
0
 
LVL 11

Expert Comment

by:emilgas
ID: 24747443
So what is it that you are looking for? What are you trying to fix that doesn't work?
0
 
LVL 20

Author Comment

by:DVation191
ID: 24747462
Everything works now - that's why I closed the question and awarded points =)
0
 
LVL 11

Expert Comment

by:emilgas
ID: 24747545
Oh, damn LOL
I didn't see that you closed it. Well, good luck
0

Featured Post

Prepare for your VMware VCP6-DCV exam.

Josh Coen and Jason Langer have prepared the latest edition of VCP study guide. Both authors have been working in the IT field for more than a decade, and both hold VMware certifications. This 163-page guide covers all 10 of the exam blueprint sections.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Problem Description:   Couple of months ago we upgraded the ADSL line at our branch office from Home to Business line. The purpose of transforming the service to have static public IP’s. We were in need for public IP’s to publish our web resour…
Creating an OSPF network that automatically (dynamically) reroutes network traffic over other connections to prevent network downtime.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

722 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question