Solved

Need help setting up IP routing to SBS 2003 with Public LAN/WAN

Posted on 2009-07-15
10
1,143 Views
Last Modified: 2012-06-21
Experts-
I received static IP addresses from AT&T.  They gave me two sets, a public WAN and a public LAN (these are obviously not the real IPs):
WAN
IPs: 89.123.11.142/143
Subnet Mask: 255.255.255.252
Gateway: 89.123.11.141
LAN
Useable IPs: 79.123.22.241/245
Subnet Mask: 255.255.255.248
Gateway: 79.123.22.246

The office consists of a DSL modem ->Linksys WRT54G router -> SBS 2003 server ->workstations
Additionally, the SBS 2003 server is a mail server with an MX record and linked to a LAN IP.  I need to be able to see the server from the Internet (ping it, send mail, remote access, etc).  SBS has a dual NIC and from what I understand is supposed to be setup with one internal NAT network and one external ISP network.

Diagram below is how I have it setup now.
 
My problem is that I cannot see the server from the Internet.  I need the Linksys router for office wireless connectivity (printers, notebooks, etc).  AT&T will not allow the LAN IPs to be on their network and they control routing from the 89.x subnet to resolve to 79.x.  I can ping both 89.x IP addresses as well as the Linksys LAN side (79.123.22.246).  But, even putting the SBS server IP (79.123.22.245) in the DMZ does not allow me to see it from the Internet.  Port forwarding also doesnt work.  Am I missing something?

Thanks,
-Joe


PerkovichNetworkIssue.jpg
0
Comment
Question by:jetcosys
  • 5
  • 3
  • 2
10 Comments
 
LVL 13

Expert Comment

by:murgroup
Comment Utility
First you need to put the DSL modem in bridged mode so that it forwards all traffice to the Linksys. My guess is the modem is doing NAT and probably has a built in firewall. your DSL provider can help you get it into bridged mode.
Then setup the LInksys with your public IP of 142 or 143, the subnet of 255.255.255.252 and gateway of 141.
Once you have internet access create port forwarding rules for your needed services to the sbs server.
Keep in mind the Linksys is a home router and not intended for business. I would purchase a business class firewall.
0
 
LVL 6

Accepted Solution

by:
Citacomp earned 250 total points
Comment Utility
If you need the Linksys router for office printers, etc., why don't you have it on the LAN side of your SBS?  This should take care of your problems.

If you need to keep the Linksys at it's place in the chain for some reason, then I would think that static routing might need to be configured on the device.
0
 

Author Comment

by:jetcosys
Comment Utility
Thanks for the quick responses!

murgroup: The modem is in bridged mode already and must be set to the WAN IP (141), so the Linksys WAN side is set to 142 and the Linksys LAN side to the 246.  That part all works as expected.  The forwarding of ports doesn't work however.  I can ping 246 and have ports forwarded to 245 (SBS Server), but the traffic never relays.  You're right, I should use a biz class router, but for a small office, this is fine.

Citacomp: interesting idea.  I actually never thought of that.  Do you know if this Linksys can be a router instead of a gateway and forward DHCP from the server?

Thanks for the help,
-Joe
0
 
LVL 13

Assisted Solution

by:murgroup
murgroup earned 250 total points
Comment Utility
Yes you can use the Linksys for wireless only. just plug it into your network and make sure it's on the same subnet at the internal LAN.
I've never heard of a Public LAN being assigned by the ISP. Normally you choose what your internal range is going to be ie 192.168.1.1-254
If the modem is in bridged mode your setup in the linksys would look like:
WAN:
Static IP: 89.123.11.142
Subnet: 255.255.255.252
Gateway: 89.123.11.141
DNS: your public DNS servers

LAN IP: 192.168.1.1 or whatever.
Subnet: 255.255.255.0

Then in SBS you would only use one NIC and it would have an IP of say:
IP: 192.168.1.5
SUB:255.255.255.0
Gateway: 192.168.1.1

Run the Internet connection wizard and tell it to use only one NIC. The defualt gateway of 192.168.1.1, your external dns servers and finish the wizard.
Everything should work fine if your modem is in bridged mode. If not the modem could be your issue.
Also I'm not sure if AT&T uses PPPoE or PPPoA. That can cause issues and the router should support PPPoE.

0
 

Author Comment

by:jetcosys
Comment Utility
Ok, will move the Linksys and see what happens.  I've never heard of the ISP giving two IP ranges either, but it's what AT&T did this time.  The reason I need the Public LAN IP is because the server is an MX and to properly register the reverse lookup in DNS, I had to have AT&T assign the IP.  I had it setup as you described above exactly but too much mail has been non-deliverable due to the reverse DNS not being the mail.server.com address.  It's a mess man.
0
Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

 
LVL 13

Expert Comment

by:murgroup
Comment Utility
Strange, AT&T should control RDNS for your public IP and it should be an easy fix on their end. I have many many clients setup like that and the ISP always controls RDNS. Good luck with this issue.
0
 
LVL 6

Expert Comment

by:Citacomp
Comment Utility
A further note about the Linksys.  When you connect it to your LAN side, don't plug anything in to the WAN port and make sure DHCP is off (assuming that the SBS is serving DHCP).  I suppose it'd be possible to use the WAN port if you turned of NAT, but instead of messing around with the configuration it's easier to just not use it.

Is your SBS Premium or Standard?
0
 

Author Comment

by:jetcosys
Comment Utility
Yah, I already disabled DHCP on the router since SBS is issuing DHCP and will plug in on the LAN side only.  SBS is standard version.  Thanks for the advice!  :)

-J
0
 

Author Comment

by:jetcosys
Comment Utility
Ok, I removed the Linksys router which did not work because my server must have an IP address on the public LAN side (79 subnet) and the DSL modem is on the WAN side (89 Subnet) which makes the gateway on the different ip segment.  Then, in looking at the options on the server NIC, I remembered that you can multi-home a single NIC.  I used the advanced TCP/IP settings and assigned the server NIC an IP address from 79, gateway from 89...then in the advanced area, an IP from 89 and the gateway from 79.  Not sure why or how, but this configuration works.
0
 

Author Closing Comment

by:jetcosys
Comment Utility
Split the points evenly between the two experts as both assisted with advice on a solution I ultimately determined.
0

Featured Post

What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

Join & Write a Comment

This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Small Business Server 2011. NOTE: This guide has been written using the preview version of SBS2011 therefore some of the screens may …
If you are a user of the discontinued Microsoft Office Accounting 2008 (MSOA) and have to move to a new computer running Windows 8, you will be unhappy to discover that it won't install.  In particular, Microsoft SQL Server 2005 Express Edition (SSE…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
This video explains how to create simple products associated to Magento configurable product and offers fast way of their generation with Store Manager for Magento tool.

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now