Solved

WAN and LAN NIC on Windows Server 2012

Posted on 2016-10-12
11
50 Views
Last Modified: 2016-11-08
I have a web portal that is both internet facing and LAN facing..  I have the WAN NIC with a public IP and gateway.  The LAN NIC only had an internal IP and no gateway.  This worked just fine, however, we setup a site to site tunnel to our office..  We also use our internal domain DNS which resolved the internal IP of the web portal..  The site to site tunnel will required the LAN NIC to have the local gateway to be able to route between the two subnets in the site to site tunnel.  Due to this I added the internal gateway to the LAN NIC.  Everything is working, however, as I understand this is not best practice..  So..  Should I change the internal DNS records to resolve the public IP so the site to site users hit the public IP or should I setup static routes on the Windows server?  I kind of like how the site to site users can access the web portal through the tunnel for that's more secure for those sessions..
0
Comment
Question by:gopher_49
11 Comments
 
LVL 42

Accepted Solution

by:
kevinhsieh earned 250 total points
ID: 41841236
I probably would not have two NICs on the server. It's way more complicated than just doing a static NAT or port forwarding to the server from your firewall or public facing router.

That said, unless you want to change your design and go single NIC, you should remove the default gateway from your LAN interface, and add static routes for and network that is inside.
0
 
LVL 38

Expert Comment

by:Aaron Tomosky
ID: 41841246
Agreed, only one gateway.
Also agreed this should be a single NIC server with a firewall/router doing the public forwarding.
0
 

Author Comment

by:gopher_49
ID: 41841285
The thing is.  I have domain resources that the server needs to access on the LAN.  And...  I want my SIP services to not deal with NATs.  That's why I have the public NIC
0
 
LVL 20

Expert Comment

by:masnrock
ID: 41846400
Why not create a DMZ? Sure, you still have a NAT situation, but it would eliminate some issues, plus improve security.
0
 

Author Comment

by:gopher_49
ID: 41852620
I have never gotten pfsense's NAT to work well with SIP...  I have to use the sipproxd module and that doesn't meet my requirements..  I guess with that said I need to stick with my current config and move to a Fortinet virtual appliance versus the pfsense..
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 
LVL 20

Assisted Solution

by:masnrock
masnrock earned 250 total points
ID: 41852655
Ahh. Sometimes it comes down to settings like SIP ALG or transformations that will cause the nightmares. Each firewall has its down way to overcome quirks like that. For example, Sonicwall has a particular patch for firmware, but you have to explicitly request it from their support, and it takes several weeks to receive it because their engineers have to work on the code.

This link may help a bit for trying to get things working with pfsense:
https://www.reddit.com/r/PFSENSE/comments/31a1y1/sip_problems_behind_pfsense_box/

But I think this 3CX guide might be even more helpful if you're trying to stick with pfsense:
http://www.3cx.com/blog/voip-howto/pfsense-firewall/
0
 

Author Comment

by:gopher_49
ID: 41852661
I've tried everything with pfsense.. In this environment I had constant issues getting SIP to work...  Will my current config work until I get a different firewall?  So far I haven't noticed any issues..
0
 
LVL 20

Expert Comment

by:masnrock
ID: 41852696
For security's sake, I'd tell you to replace the firewall if there's no way to make pfsense work. As long as it's directly connected to the network AND the internet, that server is serving as a potential gateway to hacking the network.

What type of phone system is it anyway?
0
 

Author Comment

by:gopher_49
ID: 41855697
I have the Windows Firewall on..  The datacenter DDoS attacks and has some IPS/IDS.  It's a unified communcations platform.  The SIP stack I Asterisk I think..  But there is a lot going on there.  I guess I'll look at getting a different virtual firewall.
0
 

Author Closing Comment

by:gopher_49
ID: 41879362
pfsense can be a pain in complex SIP environments...Due to this I'll just move to Fortinet's virtual firewall where I get vendor support.
0

Featured Post

Free Gift Card with Acronis Backup Purchase!

Backup any data in any location: local and remote systems, physical and virtual servers, private and public clouds, Macs and PCs, tablets and mobile devices, & more! For limited time only, buy any Acronis backup products and get a FREE Amazon/Best Buy gift card worth up to $200!

Join & Write a Comment

The article will show you how you can maintain a simple logfile of all Startup and Shutdown events on Windows servers and desktops with PowerShell. The script can be easily adapted into doing more like gracefully silencing/updating your monitoring s…
You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
In this Micro Tutorial viewers will learn how to restore single file or folder from Bare Metal backup image of their system. Tutorial shows how to restore files and folders from system backup. Often it is not needed to restore entire system when onl…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now