Untangle Networks [home]


Go Back   Untangle Forums > General Forums > Networking

Reply
 
LinkBack Thread Tools
Old 06-16-2009, 01:03 PM   #1 (permalink)
Newbie
 
Join Date: Jan 2009
Posts: 5
Default 6.2 Port Forwarding stopped after cold restart

Hello,

We have been running Untangle 6.x at the office for 3-ish months. The system did the automatic updates with no issues untill...

We have a static IP setup with 4 outside IP addresses. I had mapped 2 additional addresses to port forward HTTPS to internal servers. All was working well.

I turned down our network so we could run some new wiring and clean up the physical network. We moved the internet connections and the server rack to the other end of the room. Reconnected it all and then fired it all back up.

After that cold start everything worked as before EXCEPT port forwarding. I had even done a backup of the config before shutting the server down. I reloaded the config, and still no outside access to our 2 web servers.

I had previously changed the outside management access to another port (2443) so that it would not conflict with these forwards. I also checked to make sure it had not reverted back to the default.

I tried many of the suggestions in the forum, including deleting all port forwarding rules and starting from scratch. Nothing has worked so far to restore the forwarding. Everything else still works great and all users have internet access, and my OpenVPN connections still work. I can access the sites from the internal network, so I know the web servers are running.

I have attached a screen shot of the port forwarding rule that was working before.

I am hoping not to have to do a full re-install (and reload the config). All I did was shut it down, walk it to the other side of the room and turn it back on.

Any suggestions are greatly suggested.

Thanks,
G
Attached Images
File Type: png untangle_port_forward.png (31.7 KB, 17 views)
geegeemoe is offline   Reply With Quote
Old 06-16-2009, 01:22 PM   #2 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 5,166
Default

I can't even reach that IP - are you sure thats the right IP? Is it one of untangle's IPs?
Have you tried using "Destined Local?"
__________________

dmorris is offline   Reply With Quote
Old 06-16-2009, 01:41 PM   #3 (permalink)
Newbie
 
Join Date: Jan 2009
Posts: 5
Default

Quote:
Originally Posted by dmorris View Post
I can't even reach that IP - are you sure thats the right IP? Is it one of untangle's IPs?
Have you tried using "Destined Local?"
The actual IP address was not used. It is a private Wiki for a startup company. Sorry you wouldn't be able to access it.

-G
geegeemoe is offline   Reply With Quote
Old 06-16-2009, 01:42 PM   #4 (permalink)
Newbie
 
Join Date: Jan 2009
Posts: 5
Default

Quote:
Originally Posted by geegeemoe View Post
The actual IP address was not used. It is a private Wiki for a startup company. Sorry you wouldn't be able to access it.

-G
Specifically the IP address was edited from the screen capture in image software. The real address IS in the rule on UT. Just to clarify :-)

I tried "Destined local" in addition to the destination address. I can't just use "destination local" by itself because there are 2 external addresses being mapped to 2 different internal web servers.

-G

Last edited by geegeemoe; 06-16-2009 at 01:45 PM..
geegeemoe is offline   Reply With Quote
Old 06-16-2009, 01:54 PM   #5 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 5,166
Default

ah, i see

are you testing from the outside?

other things to try here: http://wiki.untangle.com/index.php/P...shooting_Guide
__________________

dmorris is offline   Reply With Quote
Old 06-16-2009, 02:36 PM   #6 (permalink)
Newbie
 
Join Date: Jan 2009
Posts: 5
Default

Quote:
Originally Posted by dmorris View Post
ah, i see

are you testing from the outside?

other things to try here:
Yep. We have 2 ISP's. I am using the 2nd one (optimum business) to test the inbound on the 1st (speakeasy DSL).

Okay. I am sitting here with 3 terminal windows open running tcpdump on UT eth0 (external) UT eth1 (internal) and one of the web servers eth0 (CentOS - Apache).

I see the packets come in from eth0, get translated by port forwarding and go out eth1. I then see the request come into the web server on its eth0.

If I do the request from the internal network the web server shows the responces back to my internal address. When I try from outside the return connections are not being made.

Is UT somehow blocking the reply's back to the outside request??

-George

Last edited by geegeemoe; 06-16-2009 at 02:44 PM..
geegeemoe is offline   Reply With Quote
Old 06-16-2009, 03:53 PM   #7 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 5,166
Default

great info.

is the default gateway of the web server the untangle server?

(check #2 on the list)
__________________

dmorris is offline   Reply With Quote
Old 06-16-2009, 04:11 PM   #8 (permalink)
Newbie
 
Join Date: Jan 2009
Posts: 5
Default

Ok.

Forget I ever posted. I set up another temporary web server on my laptop and did the port forwarding to it, and it worked.

Somehow even though the web servers are serving to the internal network they are not serving to addresses outside the internal ip range.

Another mystery to locate!

Thanks for the suggestions.

-G
geegeemoe is offline   Reply With Quote
Old 06-16-2009, 05:02 PM   #9 (permalink)
Master Untangler
 
Join Date: Sep 2008
URLs submitted: 1
Posts: 294
Default

Hi,

I know you mapped 2 ext addr. to int. servers. Have you tried just port forward without mapping. I've attached my port forward to my int. server via port 443 as an example.

Good Luck
Attached Images
File Type: jpg Clipboard01.jpg (35.7 KB, 10 views)
dknyinva is offline   Reply With Quote
Reply

Tags
6.2, port forward, routing

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 07:22 AM.


© 2009 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.3.2