Solved

Routing problem with proxy

Posted on 2012-04-09
10
487 Views
Last Modified: 2012-04-09
We have a windows 2008 R2 server acting as a proxy. The proxy software is Wingate 7.

2 nics installed, nic2 for the internet, nic1 for local lan.

Ethernet adapter Local Area Connection 2:

   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network Connection #2
   Physical Address. . . . . . . . . : 00-14-22-21-14-C1
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
   IPv4 Address. . . . . . . . . . . : xx.xxx.xxx.xxx(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.255.224
   Default Gateway . . . . . . . . . : xx.xxx.xxx.xxx
   DNS Servers . . . . . . . . . . . : xx.xxx.xxx.xxx
                                       xx.xxx.xxx.xxx
   NetBIOS over Tcpip. . . . . . . . : Enabled

Ethernet adapter Local Area Connection:

   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network Connection
   Physical Address. . . . . . . . . : 00-14-22-21-14-C0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
   IPv4 Address. . . . . . . . . . . : 10.10.0.6(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.0.0
   Default Gateway . . . . . . . . . : 10.10.0.254
   DNS Servers . . . . . . . . . . . : 10.10.0.5
                                       10.10.0.7
   NetBIOS over Tcpip. . . . . . . . : Enabled


10.10.0.254 is our router.
We have 3 offices, each on a seperate subnet with thier own routers. 10.10, 10.20. 10.60.
Each office has thier own router as thier gateway with matching IPs.

The issue we are having is the remote offices cannot use the proxy.
The recommended config is no gateway on the LAN nic. With this blank, the server cannot piny any computers in the remote offices, and they cannot ping back. With the gateway configured, the remote offices can ping the server, but the server cannot ping back. A tracert to a computer in one of the remote offices shows it going out through the internet connection instead of the LAN. Any clues what is wrong here?
0
Comment
Question by:summitMIS
  • 4
  • 4
  • 2
10 Comments
 
LVL 11

Expert Comment

by:emilgas
Comment Utility
The whole setup has issues. Let's start from the beginning...
How are your remote subnets connected to each other? VPN? T1 or ???
Why don't the other routers have a default gateway?
What's the DHCP, and the gateway at each location?

If you want your 10.10.0.254 to be your gateway at each location then you must specifically tell the DHCP server at each location to assign 10.10.0.254 as the default gateway. Remember you are in charge of your network settings, and if the gateway is missing then that's a separate issue on its own.
0
 

Author Comment

by:summitMIS
Comment Utility
The remote offices are connected vis T1.
Each remote office has their own gateway, as I said, they use the router in each office as thier gateway. The 10.20 subnet uses 10.20.0.254 as thier gateway, and the 10.60 subnet uses 10.60.0.254 as thier gateway, which are thier routers.
We do not use DHCP.
The gateways are the routers.
We do not want 10.10.0.254 as the gateway in the remote offices, that is our gateway at the main office. Each office has thier own gateway in thier own router.
0
 
LVL 11

Expert Comment

by:emilgas
Comment Utility
You also mentioned that
A tracert to a computer in one of the remote offices shows it going out through the internet connection instead of the LAN.
What do you meant by this? How many connections do you have at each location? You got Regular internet and T1?
0
 

Author Comment

by:summitMIS
Comment Utility
The proxy server has 2 connections, 1 for internet, 1 for lan. Each remote office has a single connection to our corporate office where the proxy is located. The problem we are having is not with the connections at the remote offices, it is with the proxy server machine. TYhe proxy server is the only computer that is having issues connectiong to the remote offices, and the only computer the remote offices are having a problem connecting to. All other servers and workstations in all offices can communicate fine.
0
 
LVL 11

Expert Comment

by:emilgas
Comment Utility
Ok let me put it this way... if you were to turn the Proxy server off, will your remote offices have internet connection? And what kind of an internet connection is the one on the server?
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 
LVL 51

Accepted Solution

by:
Keith Alabaster earned 500 total points
Comment Utility
The main office is using a /16 mask so you have a single network spanning all of the offices. Whilst you cannot put a gateway into the internal nic, you should instead use static route entries that point traffic destined for the respective class C subnets used at the remote offices to the router ip addresses that connect them to the main office.
0
 

Author Comment

by:summitMIS
Comment Utility
@emilgas,
Yes, if we do not use the proxy, the offices have internet access through our T1 in corporate.
The proxy server is using a cable connection through Cox communications.

@keith_alabaster,
Tried adding the routes, but it did not seem to make any differance, still unable to access either way.
0
 

Author Comment

by:summitMIS
Comment Utility
@keith_alabaster,
BINGO, it took a reboot, but adding the routes did the trick!
We are up and running again, thanks!
0
 
LVL 11

Expert Comment

by:emilgas
Comment Utility
that's your problem. you can't have another path to the internet if you want your users to go through the Proxy/Cox. When I say you can't I don't mean physically. Of course you can have multiple internet connections but you have to design it properly. It seems that the initial design of your network was not planned out correctly, or it was not planned with this Cox connection in mind.

Anyways, tell me more about your corporate and how many connection they have, and how all the T1's tie in together, and what kind of routing protocols you use or if everything is statically managed. When you have two routes to the internet then there needs to be more configuration on the corporate core router since you have multiple ways to get out.

Ideally if you had just T1's connecting all your offices together and one internet connection to the outside world via Cox then your setup would have been simpler. You could have just made one default route to the public internet by pointing everything to your Proxy, which in return routes everything to Cox.
0
 
LVL 51

Expert Comment

by:Keith Alabaster
Comment Utility
More than welcome :)
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Don’t let your business fall victim to the coming apocalypse – use our Survival Guide for the Fax Apocalypse to identify the risks and signs of zombie fax activities at your business.
Data center, now-a-days, is referred as the home of all the advanced technologies. In-fact, most of the businesses are now establishing their entire organizational structure around the IT capabilities.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now