Solved

Watchguard Issues

Posted on 2014-04-12
3
633 Views
Last Modified: 2014-04-13
Hello!
I have a Watchguard XTM 25 and systems on two subnets.  Subnet A is 10.0.0.xxx and Subnet B is 192.168.1.xxx.  From the 10.0.0.xxx I can ping a Windows 2008 R2 server IP on the 192 subnet.  From the 192 subnet, I cannot ping anything on the 10 network.  I can ping the default 192 gateway which is set up as a VLAN on Port 2, and the default gateway for the 192 network is on an HP Procurve 2848 switch (also pingable).

How can I get the Windows 2008 R2 server on the 192 network to talk to the 10 network.

Also, I cannot RDP from the 10 network to the 192 network.  I receive the following error when attempting to RDP:
2014-04-12 20:49:33 Deny 10.0.0.64 192.168.1.244 1900/udp 33895 1900 1-Trusted 2-VLAN 100 Denied 501 63 (Unhandled Internal Packet-00)  proc_id="firewall" rc="101"       Traffic

Any assistance would be appreciated.

Thank you!
0
Comment
Question by:swlaurie
  • 2
3 Comments
 
LVL 25

Expert Comment

by:Zephyr ICT
ID: 39997070
Besides possible issues with routing, did you open the necessary ports/holes in the firewall?

e.g:

- Port for Remote Desktop --> 10.x.x >> TCP 3389 >> 192.x.x
- Allow ICMP Echo from 192.x.x on the 10.x.x network
0
 

Author Comment

by:swlaurie
ID: 39997206
Spravtek,
I am a complete noob to the WG line. How would I go about setting the above up?
0
 
LVL 25

Accepted Solution

by:
Zephyr ICT earned 500 total points
ID: 39997259
Well ... Good question, I don't have a WG myself, thought you would be able to get in there and get going ;)

Maybe if you post some screenshots? Can you tell us where exactly you get stuck?

There's an endless amount of possibilities with Firewalls, it can be routing, though I doubt it, it can be that you just need to enable some policies...

For starters, check what policies are enabled: Firewall > Firewall Policies

Try to add a policy from the templates, maybe there's one for Remote Desktop? If not, you could create a policy for port 3389 for example ...

You'll probably need to check the aliases of your network, see which one is trusted and such things...

I don't know what you want to open on the network, is the 10.x.x considered as the outside network or DMZ? ...

Hope this helps you on your way ... I know it's not ideal, it's difficult without eyes on the device/interface :)
0

Featured Post

Network it in WD Red

There's an industry-leading WD Red drive for every compatible NAS system to help fulfill your data storage needs. With drives up to 8TB, WD Red offers a wide array of solutions for customers looking to build the biggest, best-performing NAS storage solution.  

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
jump server vs push server 6 153
extend vlan through a layer 3 connection 31 100
P2P and MPLS 3 45
HP Switches - Stacked to the max but need more ports, can I? 3 40
Hello All, I have been training on Multicast for a while now and whenever I start the topic , I find out that my friends /  Colleagues mention that they do not know how to test Multicast Joins. As most of the multicast would be video traffic and …
Imagine you have a shopping list of items you need to get at the grocery store. You have two options: A. Take one trip to the grocery store and get everything you need for the week, or B. Take multiple trips, buying an item at a time, to achieve t…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Hi friends,  in this video  I'll show you how new windows 10 user can learn the using of windows 10. Thank you.

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now