Solved

WAN and LAN NIC on Windows Server 2012

Posted on 2016-10-12
11
239 Views
Last Modified: 2016-11-08
I have a web portal that is both internet facing and LAN facing..  I have the WAN NIC with a public IP and gateway.  The LAN NIC only had an internal IP and no gateway.  This worked just fine, however, we setup a site to site tunnel to our office..  We also use our internal domain DNS which resolved the internal IP of the web portal..  The site to site tunnel will required the LAN NIC to have the local gateway to be able to route between the two subnets in the site to site tunnel.  Due to this I added the internal gateway to the LAN NIC.  Everything is working, however, as I understand this is not best practice..  So..  Should I change the internal DNS records to resolve the public IP so the site to site users hit the public IP or should I setup static routes on the Windows server?  I kind of like how the site to site users can access the web portal through the tunnel for that's more secure for those sessions..
0
Comment
Question by:gopher_49
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
11 Comments
 
LVL 42

Accepted Solution

by:
kevinhsieh earned 250 total points
ID: 41841236
I probably would not have two NICs on the server. It's way more complicated than just doing a static NAT or port forwarding to the server from your firewall or public facing router.

That said, unless you want to change your design and go single NIC, you should remove the default gateway from your LAN interface, and add static routes for and network that is inside.
0
 
LVL 39

Expert Comment

by:Aaron Tomosky
ID: 41841246
Agreed, only one gateway.
Also agreed this should be a single NIC server with a firewall/router doing the public forwarding.
0
 

Author Comment

by:gopher_49
ID: 41841285
The thing is.  I have domain resources that the server needs to access on the LAN.  And...  I want my SIP services to not deal with NATs.  That's why I have the public NIC
0
How Blockchain Is Impacting Every Industry

Blockchain expert Alex Tapscott talks to Acronis VP Frank Jablonski about this revolutionary technology and how it's making inroads into other industries and facets of everyday life.

 
LVL 29

Expert Comment

by:masnrock
ID: 41846400
Why not create a DMZ? Sure, you still have a NAT situation, but it would eliminate some issues, plus improve security.
0
 

Author Comment

by:gopher_49
ID: 41852620
I have never gotten pfsense's NAT to work well with SIP...  I have to use the sipproxd module and that doesn't meet my requirements..  I guess with that said I need to stick with my current config and move to a Fortinet virtual appliance versus the pfsense..
0
 
LVL 29

Assisted Solution

by:masnrock
masnrock earned 250 total points
ID: 41852655
Ahh. Sometimes it comes down to settings like SIP ALG or transformations that will cause the nightmares. Each firewall has its down way to overcome quirks like that. For example, Sonicwall has a particular patch for firmware, but you have to explicitly request it from their support, and it takes several weeks to receive it because their engineers have to work on the code.

This link may help a bit for trying to get things working with pfsense:
https://www.reddit.com/r/PFSENSE/comments/31a1y1/sip_problems_behind_pfsense_box/

But I think this 3CX guide might be even more helpful if you're trying to stick with pfsense:
http://www.3cx.com/blog/voip-howto/pfsense-firewall/
0
 

Author Comment

by:gopher_49
ID: 41852661
I've tried everything with pfsense.. In this environment I had constant issues getting SIP to work...  Will my current config work until I get a different firewall?  So far I haven't noticed any issues..
0
 
LVL 29

Expert Comment

by:masnrock
ID: 41852696
For security's sake, I'd tell you to replace the firewall if there's no way to make pfsense work. As long as it's directly connected to the network AND the internet, that server is serving as a potential gateway to hacking the network.

What type of phone system is it anyway?
0
 

Author Comment

by:gopher_49
ID: 41855697
I have the Windows Firewall on..  The datacenter DDoS attacks and has some IPS/IDS.  It's a unified communcations platform.  The SIP stack I Asterisk I think..  But there is a lot going on there.  I guess I'll look at getting a different virtual firewall.
0
 

Author Closing Comment

by:gopher_49
ID: 41879362
pfsense can be a pain in complex SIP environments...Due to this I'll just move to Fortinet's virtual firewall where I get vendor support.
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I'm a big fan of Windows' offline folder caching and have used it on my laptops for over a decade.  One thing I don't like about it, however, is how difficult Microsoft has made it for the cache to be moved out of the Windows folder.  Here's how to …
Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
In this Micro Tutorial viewers will learn how to use Windows Server Backup to create full image of their system. Tutorial shows how to install Windows Server Backup Feature on Windows 2012R2 and how to configure scheduled Bare Metal Recovery backup.…
In this Micro Tutorial viewers will learn how they can get their files copied out from their unbootable system without need to use recovery services. As an example non-bootable Windows 2012R2 installation is used which has boot problems.

626 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question