Solved

Unable to access Apache Server from Outside the LAN

Posted on 2012-04-04
16
847 Views
Last Modified: 2012-04-09
We are running Apache 2.2 on Windows Server 2008 R2.
We have developed a php/sql application and it runs just fine when accessed from within the lan (i.e: http://myapp.domain.local)

We are however struggling to make the application accessible from outside the our lan using http://myapp.domain.int

We have allowed port 80 in the Windows and ASA firewall. We have also setup a nat rule. The resource is published to dns. However the application is still not accessible.

We are stumped and no one is really an Apache expert onsite.

The application is stored at C:\Server\www\savsvr000020a.sacu.local\public_html

I am also attaching out httpd confing file for assistance and guidance.

Please help
httpd.txt
0
Comment
Question by:SACUADMIN
  • 8
  • 4
  • 2
  • +1
16 Comments
 
LVL 28

Expert Comment

by:chilternPC
ID: 37806156
you say you have set up a firewall to allow http through - is that part of the Router? (i.e the box that interfaces to your internet)

  my firewall and router are in the same box so I figure a port forwarding rule to allow port 80 (or whatever post my application uses)  to route  to a particular ip address on my local LAN from the outside world.
0
 
LVL 28

Expert Comment

by:chilternPC
ID: 37806171
also I found if you are testing it by trying to  go out from your LAN and back in to your LAN it won't work - (some kind of loopback protect) try it from a system truely outside your LAN,
0
 

Author Comment

by:SACUADMIN
ID: 37806207
Hi ChiternPC,

The router is not part of the firewall. We are however publishing other websites through it using NAT with no problems. The ISP does not block anything, just gives us a public IP with all ports open.

I am testing strictly from outside our LAN to avoid any loopback issues.

I just feel i am missing something with Apache.
0
 
LVL 3

Expert Comment

by:unsatiated
ID: 37806219
From an outside source, can you telnet to port 80 on the external IP address?  Does your apache server have a default gateway set as your firewall?
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 37806227
Is the app using any other ports?
0
 

Author Comment

by:SACUADMIN
ID: 37806407
Default gateway is set to firewall ip.

Interestingly I cannot telnet to port 80 on the external IP.
So it must be a firewall issue? (ASA 5505)
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 37806427
Could you show a (sanitized) config of the ASA?
0
 

Author Comment

by:SACUADMIN
ID: 37806506
banner motd **** Unauthorized Use or Access Prohibited ****
ftp mode passive
clock timezone WAST 1
clock summer-time WADT recurring 1 Sun Sep 2:00 1 Sun Apr 2:00
dns domain-lookup outside
dns server-group DefaultDNS
 name-server 196.44.128.146
 name-server 196.44.136.165
 domain-name sacu.local
object-group protocol TCPUDP
 protocol-object udp
 protocol-object tcp
access-list outside_in extended permit icmp any any time-exceeded
access-list outside_in extended permit icmp any any echo-reply

"....sanitized stuff....."

access-list outside_in extended permit tcp any host 41.205.140.13 eq www
access-list inside_nat0_outbound extended permit ip 10.9.8.0 255.255.255.0 10.9.8.0 255.255.255.0
access-list LOCAL-LAN-VPN standard permit 10.9.8.0 255.255.255.0

".....sanitized stuff..."

global (outside) 1 interface
nat (inside) 0 access-list inside_nat0_outbound
nat (inside) 1 0.0.0.0 0.0.0.0
static (inside,outside) 41.205.140.13 10.9.8.55 netmask 255.255.255.255

"...............santized stuff............."

access-group outside_in in interface outside
route outside 0.0.0.0 0.0.0.0 41.205.140.9 1
---------------------

the server with problems is the "41.205.140.13"
0
NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

 
LVL 35

Expert Comment

by:Ernie Beek
ID: 37806609
Well that should be ok.
You said it was a php/sql app. Are you sure it's only using port 80?

One other thing I found. In the httpd there is a line: ServerName localhost I think that should be: myapp.domain.int localhost:80 as stated on: http://www.ehow.com/how_6049004_do-connections-access-apache-server_.html
0
 

Author Comment

by:SACUADMIN
ID: 37806745
Thanks Erniebeek,

When I add "myapp.domain.int localhost:80" to the httpd file the Apache fails to start.

I earlier opened the ASA firewall for all tcp,upd,ip connections. Even turned off the Windows firewall. No joy... So I don't think it is strictly a port issue
0
 
LVL 3

Expert Comment

by:unsatiated
ID: 37806809
Perhaps adjusting this in apache config:

ServerName localhost

set to

ServerName 10.9.8.55
0
 

Author Comment

by:SACUADMIN
ID: 37806987
No joy either way unsatiated. The Apache server starts but is still only accessible from within the LAN
0
 

Author Comment

by:SACUADMIN
ID: 37807000
When i run a port scanner from within the LAN, port 80 is open on the server.
When I try from outside the lan using yougetsignal.com it is closed. Aaggghhhh.... I need some coffee
0
 

Accepted Solution

by:
SACUADMIN earned 0 total points
ID: 37807196
I resolved it finally.
(a) Added a second ip to the server, with no internal dns but with firewall ip as gateway.
(b) NAT'd the new IP
(c) Changed httpd back to "Listen 80" and "ServerName localhost:80"

All is working just fine website acessible from outside LAN and inside the LAN.
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 37809887
Glad you figured it out, good job :)
0
 

Author Closing Comment

by:SACUADMIN
ID: 37822737
It is likely that Apache and some other service were clashing at Port 80 therefore a new IP resolved the problem.
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
xampp tool 12 28
mysqli 3 22
myqsl update statement on phpMyAdmin 8 22
Sql query on a varchar that is numeric. 8 27
If your site has a few sections that need to be secure when data is transmitted between the server and local computer, such as a /order/ section for ordering or /customer/ which contains customer data, etc it would of course be recommended to secure…
Nothing in an HTTP request can be trusted, including HTTP headers and form data.  A form token is a tool that can be used to guard against request forgeries (CSRF).  This article shows an improved approach to form tokens, making it more difficult to…
Explain concepts important to validation of email addresses with regular expressions. Applies to most languages/tools that uses regular expressions. Consider email address RFCs: Look at HTML5 form input element (with type=email) regex pattern: T…
The viewer will learn how to look for a specific file type in a local or remote server directory using PHP.

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now