Solved

Natting

Posted on 2015-01-29
2
134 Views
Last Modified: 2015-02-01
I have only 1 public ip, although I have 2 applications on port 443 that need to be usable externally.  Is there something else I can do to get them both natted to the outside?
0
Comment
Question by:Jack_son_
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 30

Assisted Solution

by:Rich Weissler
Rich Weissler earned 250 total points
ID: 40578819
A reverse proxy comes to mind.
0
 
LVL 3

Accepted Solution

by:
Stephen Berk earned 250 total points
ID: 40578943
NAT is happening at the IP and TCP layers, so you either need another IP address or you need to move one of your TCP/443 apps to a different port. It probably isn't feasible to move the app to a different port (assuming its public facing), so a 2nd IP address is probably your easiest and/or cheapest option.

That said, Rich is right on with his suggestion of a reverse proxy. I use F5 Big-IP's in this setup and let the URI's of the various web apps dictate how I will forward traffic to the servers being proxied. Here's a doc from F5 that gives an intro to URI translation (http://goo.gl/zyWGWN) and how the Big-IP proxies traffic. Don't get lost in the details, it's really just to show you what conceptually what's happening. And don't think you need an F5 solution to get a reverse proxy for web traffic. The Big-IP is an enterprise solution that handles much more than reverse proxying. Apache, Nginx, and Squid are all software proxies you can load onto a Linux server.

The Q&D: 443 traffic comes in from the Internet, the firewall NAT's to an address on the reverse proxy, the reverse proxy examines the URI and forwards to some web server.
0

Featured Post

Prepare for your VMware VCP6-DCV exam.

Josh Coen and Jason Langer have prepared the latest edition of VCP study guide. Both authors have been working in the IT field for more than a decade, and both hold VMware certifications. This 163-page guide covers all 10 of the exam blueprint sections.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

SSL is a very common protocol used these days when browsing the web.  The purpose is to provide security to communication, but how does it do it?  There are several pieces at work that have to be setup before SSL will even work and it requires both …
David Varnum recently wrote up his impressions of PRTG, based on a presentation by my colleague Christian at Tech Field Day at VMworld in Barcelona. Thanks David, for your detailed and honest evaluation!
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…
In this video we outline the Physical Segments view of NetCrunch network monitor. By following this brief how-to video, you will be able to learn how NetCrunch visualizes your network, how granular is the information collected, as well as where to f…

623 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question