Solved

How to route traffic on same port (443) to multiple internal Servers?

Posted on 2013-01-26
10
73 Views
Last Modified: 2015-06-23
I am sure this is a networking 101 thing but never had to really deal with this before. So I have a number if internal resources (ActiveSync, RDS) that are on different Servers but both run on port 443. We only have one public IP.

So how do we configure this so that traffic for both reaches its destination?
0
Comment
Question by:Flipp
10 Comments
 
LVL 24

Expert Comment

by:smckeown777
Comment Utility
I don't think this is possible, since from the outside how does the router decide to send traffic to the ActiveSync server rather than the RDS server?

With port forwarding it sends to 1 internal client, so with only 1 public IP the normal way to make this work is to change ports on the internal server to alternate...i.e. if I have 2 servers running RDS on port 3389(default) then I'd have to change the 2nd server to use an alternate port(3390 for example) and port forward on the router to 3390 for the 2nd server...
0
 
LVL 6

Author Comment

by:Flipp
Comment Utility
Well I figured thats what multiple public IPs would do ... then you port forward from a.a.a.a:443 to Server1 and b.b.b.b:443 to Server2.

In theory it sounds right (as long as the Router can recognise multiple public IP, but need to get something going in next few days so hoping EE can help me through.
0
 
LVL 24

Expert Comment

by:smckeown777
Comment Utility
Most business class routers will allow multiple public IP's - what model do you have?

What services are you looking to access? RDS? Is that Remote Desktop Services? Cause that's one I would say you can change to 3390 without much hassle to the end user, but ActiveSync really needs to stay on 443 since you'd have a lot of external configurations to update(phones etc)
0
 
LVL 6

Author Comment

by:Flipp
Comment Utility
Yes ActiveSync on 443, but looking at using RD Gateway which needs 443 as well. I am interested about your comment above about changing RDP to 3390 though.
Would this be better than 3389 though?

Sonicwall TZ210.
0
Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

 
LVL 15

Expert Comment

by:Frabble
Comment Utility
A situation like this can be dealt with by using a reverse proxy. Which back end server or servers to connect to is based on the FQDN used by the client. For example, client connections using the URL as.mydomain.com would be configured to go to the ActiveSync server, rds.mydomain.com to the RDS server.
What you use would probably depend on what in-house expertise and platforms you have. Microsoft ISA server, Open Source Squid or hardware load balancing appliances from Cisco, F5 or Riverbed would do what you want.
0
 
LVL 24

Accepted Solution

by:
smckeown777 earned 500 total points
Comment Utility
Sorry, I was using the 3389 as an example...

From what I know about RD Gateway(not much as I've never used it) you can't change its port from 443...obviously that's probably why you are here ;)

I doubt you are stuck with this as is...lets see if any other experts have a solution, but without seperate public IP's this one may be a dead end...
0
 
LVL 6

Author Comment

by:Flipp
Comment Utility
None of which we have ..... I think another public IP sounds easier and less complex.
0
 
LVL 6

Author Comment

by:Flipp
Comment Utility
I think I will go with 3389 for Users for the moment but would prefer 443. I will have a 2nd public IP next week so will then convert to 443 after wards.
0
 
LVL 34

Expert Comment

by:Seth Simmons
Comment Utility
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

Want to promote your upcoming event?

Are you going to an event? Are you going to be exhibiting at a tradeshow? Talking at a conference? Using a promotional banner in your email signature ensures that your organization’s most important contacts stay in the know and can potentially spread the word about the event.

Join & Write a Comment

Suggested Solutions

Even if you have implemented a Mobile Device Management solution company wide, it is a good idea to make sure you are taking into account all of the major risks to your electronic protected health information (ePHI).
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now