[Webinar] Streamline your web hosting managementRegister Today

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 657
  • Last Modified:

NAT Watchguard question two exchange servers, mail not going out.

We have two Exchange servers, one 2003 one 2010. We have a block of 10 IP's.  The configuration is similar to below.

2003 box
Internal IP 192.168.1.254
External IP 44.44.44.10

2010 box
Internal IP 192.168.1.253
External IP 44.44.44.11

I forwarded 80, 443, and 3389 from 44.44.44.11 to 192.168.1.253 just like the 2003 box is forwareded. The problem is when I set up NAT.  I configured 1 to 1 NAT just like the 2003 box, but the external IP is not showing correctly.  I then make a Dynamic NAT exception, just like the 2003 box, but then mail wont go out from the 2010 box.
0
level9tech
Asked:
level9tech
  • 4
  • 2
1 Solution
 
level9techAuthor Commented:
Anyone?  I can provide screen shots, ect.
0
 
sire_harveyCommented:
what about SMTP port 25?
0
 
dpk_walCommented:
What is the version of WG software you are running.

If running version 7,x then you would also need to add dynamic NAT exception [not needed in version 8.x or higher]
Step 11 in article below [please check all the steps]:
http://watchguard.custhelp.com/app/answers/detail/a_id/2008/kw/1-1%20NAT%20setup/session/L3NpZC9pZTNQZ1M3aw%3D%3D

To verify if you go to website, http:www.whatismyip.com; you see the external IP of WG and not the 44.44.44.11 IP.

Another thing I can think of is that the 44.44.44.11 IP is also added under external alias; remove this IP from external alias as this IP is used with 1-1 NAT.
Steps to configure external alias:
http://watchguard.custhelp.com/app/answers/detail/a_id/1704/session/L3NpZC9pZTNQZ1M3aw%3D%3D

Please check and update.

Thank you.
0
The Firewall Audit Checklist

Preparing for a firewall audit today is almost impossible.
AlgoSec, together with some of the largest global organizations and auditors, has created a checklist to follow when preparing for your firewall audit. Simplify risk mitigation while staying compliant all of the time!

 
level9techAuthor Commented:
Incoming from Any to 44.44.44.10 (2003 Box)
Outgoing from Any to Any.
0
 
level9techAuthor Commented:
dpk_wal YOU ROCK!!!

I removed it from the alias and it worked right away.

THANKS!!!!
0
 
level9techAuthor Commented:
Thanks!!
0
 
dpk_walCommented:
Happy to be of assistance! :)
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

  • 4
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now