Solved

WAN and LAN NIC on Windows Server 2012

Posted on 2016-10-12
11
130 Views
Last Modified: 2016-11-08
I have a web portal that is both internet facing and LAN facing..  I have the WAN NIC with a public IP and gateway.  The LAN NIC only had an internal IP and no gateway.  This worked just fine, however, we setup a site to site tunnel to our office..  We also use our internal domain DNS which resolved the internal IP of the web portal..  The site to site tunnel will required the LAN NIC to have the local gateway to be able to route between the two subnets in the site to site tunnel.  Due to this I added the internal gateway to the LAN NIC.  Everything is working, however, as I understand this is not best practice..  So..  Should I change the internal DNS records to resolve the public IP so the site to site users hit the public IP or should I setup static routes on the Windows server?  I kind of like how the site to site users can access the web portal through the tunnel for that's more secure for those sessions..
0
Comment
Question by:gopher_49
11 Comments
 
LVL 42

Accepted Solution

by:
kevinhsieh earned 250 total points
ID: 41841236
I probably would not have two NICs on the server. It's way more complicated than just doing a static NAT or port forwarding to the server from your firewall or public facing router.

That said, unless you want to change your design and go single NIC, you should remove the default gateway from your LAN interface, and add static routes for and network that is inside.
0
 
LVL 39

Expert Comment

by:Aaron Tomosky
ID: 41841246
Agreed, only one gateway.
Also agreed this should be a single NIC server with a firewall/router doing the public forwarding.
0
 

Author Comment

by:gopher_49
ID: 41841285
The thing is.  I have domain resources that the server needs to access on the LAN.  And...  I want my SIP services to not deal with NATs.  That's why I have the public NIC
0
Create the perfect environment for any meeting

You might have a modern environment with all sorts of high-tech equipment, but what makes it worthwhile is how you seamlessly bring together the presentation with audio, video and lighting. The ATEN Control System provides integrated control and system automation.

 
LVL 25

Expert Comment

by:masnrock
ID: 41846400
Why not create a DMZ? Sure, you still have a NAT situation, but it would eliminate some issues, plus improve security.
0
 

Author Comment

by:gopher_49
ID: 41852620
I have never gotten pfsense's NAT to work well with SIP...  I have to use the sipproxd module and that doesn't meet my requirements..  I guess with that said I need to stick with my current config and move to a Fortinet virtual appliance versus the pfsense..
0
 
LVL 25

Assisted Solution

by:masnrock
masnrock earned 250 total points
ID: 41852655
Ahh. Sometimes it comes down to settings like SIP ALG or transformations that will cause the nightmares. Each firewall has its down way to overcome quirks like that. For example, Sonicwall has a particular patch for firmware, but you have to explicitly request it from their support, and it takes several weeks to receive it because their engineers have to work on the code.

This link may help a bit for trying to get things working with pfsense:
https://www.reddit.com/r/PFSENSE/comments/31a1y1/sip_problems_behind_pfsense_box/

But I think this 3CX guide might be even more helpful if you're trying to stick with pfsense:
http://www.3cx.com/blog/voip-howto/pfsense-firewall/
0
 

Author Comment

by:gopher_49
ID: 41852661
I've tried everything with pfsense.. In this environment I had constant issues getting SIP to work...  Will my current config work until I get a different firewall?  So far I haven't noticed any issues..
0
 
LVL 25

Expert Comment

by:masnrock
ID: 41852696
For security's sake, I'd tell you to replace the firewall if there's no way to make pfsense work. As long as it's directly connected to the network AND the internet, that server is serving as a potential gateway to hacking the network.

What type of phone system is it anyway?
0
 

Author Comment

by:gopher_49
ID: 41855697
I have the Windows Firewall on..  The datacenter DDoS attacks and has some IPS/IDS.  It's a unified communcations platform.  The SIP stack I Asterisk I think..  But there is a lot going on there.  I guess I'll look at getting a different virtual firewall.
0
 

Author Closing Comment

by:gopher_49
ID: 41879362
pfsense can be a pain in complex SIP environments...Due to this I'll just move to Fortinet's virtual firewall where I get vendor support.
0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The reason that corporations and businesses use Windows servers is because it supports custom modifications to adapt to the business and what it needs. Most individual users won’t need such powerful options. Here I’ll explain how you can enable Wind…
You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
In this Micro Tutorial viewers will learn how to use Windows Server Backup to create full image of their system. Tutorial shows how to install Windows Server Backup Feature on Windows 2012R2 and how to configure scheduled Bare Metal Recovery backup.…
This tutorial will walk an individual through the process of installing of Data Protection Manager on a server running Windows Server 2012 R2, including the prerequisites. Microsoft .Net 3.5 is required. To install this feature, go to Server Manager…

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question