Link to home
Start Free TrialLog in
Avatar of RogerIvy
RogerIvy

asked on

Linux firewalls on Hyper-V can't connect to external network

Hi Experts

I have a Hyper-V server at a data center (collocated) on which I'm trying to install a Linux firewall to handle security and simple port forwarding.

- I'm using a legacy network adapter
- I have checked with the hosting company: IP address, mask, broadcast and gateway all correct.
- My internal (green) virtual network is working flawlessly on 10.0.0.10 (255.0.0.0), no physical NIC
- My external (red) isn't working. I can ping to it from my hyper-v on same subnet but I can't ping anything from it (it can ping its own public IP). It's on IP 92.60.107.61 (255.255.255.128) with broadcast 92.60.107.127 and gateway 92.60.107.1
- I've also tried Smoothwall, Edian, Monowall, Ubuntu ... all same result

Any ideas?
Avatar of Kerem ERSOY
Kerem ERSOY

Hi,

It does not seem to me that this is an issue with the firewall itself. If nobody could ping it it might be an issue with default gateway. Please make sure that the default gateway points to a valid address.

The default gateway over your host most have the DG located over the segment same as your RED interface otherwise it can not route the traffic.

Cheers,
K.
Avatar of RogerIvy

ASKER

KeremE, I'm wondering if the issue isn't related to the Hyper-v/Linux setup because:
1. All my windows VMs are able to be set up with external NICS (therefore public IPs) and can ping, browse etc.
2. None of my Linux VMs can use an external NIC (with public IP).

In theory the DG is working - for Windows VMs anyway.

What I don't know is:
- Is the problem with my overall system?
- Is it possible that the hosting company (data center) have a strange setup that Windows doesn't mind and Linux can't work with?
ASKER CERTIFIED SOLUTION
Avatar of Pierre François
Pierre François
Flag of Belgium image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Pfrancois, I've made several changes to the setup without success. There is a limit to what I can do because I don't want to lock myself out of the server.

I may try that when I am physically at the server.