?
Solved

How to route traffic on same port (443) to multiple internal Servers?

Posted on 2013-01-26
10
Medium Priority
?
93 Views
Last Modified: 2015-06-23
I am sure this is a networking 101 thing but never had to really deal with this before. So I have a number if internal resources (ActiveSync, RDS) that are on different Servers but both run on port 443. We only have one public IP.

So how do we configure this so that traffic for both reaches its destination?
0
Comment
Question by:Flipp
9 Comments
 
LVL 24

Expert Comment

by:smckeown777
ID: 38824020
I don't think this is possible, since from the outside how does the router decide to send traffic to the ActiveSync server rather than the RDS server?

With port forwarding it sends to 1 internal client, so with only 1 public IP the normal way to make this work is to change ports on the internal server to alternate...i.e. if I have 2 servers running RDS on port 3389(default) then I'd have to change the 2nd server to use an alternate port(3390 for example) and port forward on the router to 3390 for the 2nd server...
0
 
LVL 6

Author Comment

by:Flipp
ID: 38824027
Well I figured thats what multiple public IPs would do ... then you port forward from a.a.a.a:443 to Server1 and b.b.b.b:443 to Server2.

In theory it sounds right (as long as the Router can recognise multiple public IP, but need to get something going in next few days so hoping EE can help me through.
0
 
LVL 24

Expert Comment

by:smckeown777
ID: 38824034
Most business class routers will allow multiple public IP's - what model do you have?

What services are you looking to access? RDS? Is that Remote Desktop Services? Cause that's one I would say you can change to 3390 without much hassle to the end user, but ActiveSync really needs to stay on 443 since you'd have a lot of external configurations to update(phones etc)
0
Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

 
LVL 6

Author Comment

by:Flipp
ID: 38824048
Yes ActiveSync on 443, but looking at using RD Gateway which needs 443 as well. I am interested about your comment above about changing RDP to 3390 though.
Would this be better than 3389 though?

Sonicwall TZ210.
0
 
LVL 15

Expert Comment

by:Frabble
ID: 38824053
A situation like this can be dealt with by using a reverse proxy. Which back end server or servers to connect to is based on the FQDN used by the client. For example, client connections using the URL as.mydomain.com would be configured to go to the ActiveSync server, rds.mydomain.com to the RDS server.
What you use would probably depend on what in-house expertise and platforms you have. Microsoft ISA server, Open Source Squid or hardware load balancing appliances from Cisco, F5 or Riverbed would do what you want.
0
 
LVL 24

Accepted Solution

by:
smckeown777 earned 2000 total points
ID: 38824057
Sorry, I was using the 3389 as an example...

From what I know about RD Gateway(not much as I've never used it) you can't change its port from 443...obviously that's probably why you are here ;)

I doubt you are stuck with this as is...lets see if any other experts have a solution, but without seperate public IP's this one may be a dead end...
0
 
LVL 6

Author Comment

by:Flipp
ID: 38824058
None of which we have ..... I think another public IP sounds easier and less complex.
0
 
LVL 6

Author Comment

by:Flipp
ID: 38824061
I think I will go with 3389 for Users for the moment but would prefer 443. I will have a 2nd public IP next week so will then convert to 443 after wards.
0
 
LVL 36

Expert Comment

by:Seth Simmons
ID: 40845602
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you’re involved with your company’s wide area network (WAN), you’ve probably heard about SD-WANs. They’re the “boy wonder” of networking, ostensibly allowing companies to replace expensive MPLS lines with low-cost Internet access. But, are they …
In this article, we’ll look at how to deploy ProxySQL.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
In this video we outline the Physical Segments view of NetCrunch network monitor. By following this brief how-to video, you will be able to learn how NetCrunch visualizes your network, how granular is the information collected, as well as where to f…

616 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question