Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Natting

Posted on 2015-01-29
2
Medium Priority
?
139 Views
Last Modified: 2015-02-01
I have only 1 public ip, although I have 2 applications on port 443 that need to be usable externally.  Is there something else I can do to get them both natted to the outside?
0
Comment
Question by:Jack_son_
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 30

Assisted Solution

by:Rich Weissler
Rich Weissler earned 1000 total points
ID: 40578819
A reverse proxy comes to mind.
0
 
LVL 3

Accepted Solution

by:
Stephen Berk earned 1000 total points
ID: 40578943
NAT is happening at the IP and TCP layers, so you either need another IP address or you need to move one of your TCP/443 apps to a different port. It probably isn't feasible to move the app to a different port (assuming its public facing), so a 2nd IP address is probably your easiest and/or cheapest option.

That said, Rich is right on with his suggestion of a reverse proxy. I use F5 Big-IP's in this setup and let the URI's of the various web apps dictate how I will forward traffic to the servers being proxied. Here's a doc from F5 that gives an intro to URI translation (http://goo.gl/zyWGWN) and how the Big-IP proxies traffic. Don't get lost in the details, it's really just to show you what conceptually what's happening. And don't think you need an F5 solution to get a reverse proxy for web traffic. The Big-IP is an enterprise solution that handles much more than reverse proxying. Apache, Nginx, and Squid are all software proxies you can load onto a Linux server.

The Q&D: 443 traffic comes in from the Internet, the firewall NAT's to an address on the reverse proxy, the reverse proxy examines the URI and forwards to some web server.
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

We recently endured a series of broadcast storms that caused our ISP to shut us down for brief periods of time. After going through a multitude of tests, we determined that the issue was related to Intel NIC drivers on some new HP desktop computers …
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
In this video we outline the Physical Segments view of NetCrunch network monitor. By following this brief how-to video, you will be able to learn how NetCrunch visualizes your network, how granular is the information collected, as well as where to f…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…

721 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question