Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Configure firewall to allow external ip access to server

Status
Not open for further replies.

meiyaps

Technical User
Oct 20, 2003
5
US
Hi,
I am not familiar with configuring firewalls and I need to allow access to an external ip (a.b.c.0/24) access to our oracle server. We run the GNAT Box Firewall GB Pro on our network.
I am not sure if I am doing it the right way. To give you a picture of our network, we have
lets say external network ---> 210.160.52.26/24
protected -----> 192.128.100.1/24
psn --------> 152.128.128.100/24
Default Gateway ---> 210.160.52.25

This is what I need to do:
provide access from a.b.c.0/24 to 152.128.128.1
The company that requires access to our oracle server hosts our website. And our website ip address is a.b.c.59

I checked the website below and tried to follow the same procedure to allow access to our server.
I had to create an Alias because I had to allow access to the a.b.c.0 network and not just a single ip address. But, as soon as I entered this alias say TEST ----> a.b.c.0/24 (i.e., net mask 255.255.255.0) on the firewall, we immediately could not access our website from within our internal network. Remember, our website is hosted by this same company and takes the same form a.b.c.59 . I don't know why this happened, but as soon as I disabled this alias, we could access our website again. What have I done wrong here?

Since I had trouble with this first step itself, I really couldn't proceed, but I went ahead and tried to create the inbound tunnel. I created the tunnel using TCP protocol from this alias TEST to our oracle server 152.128.128.1. I have another question here. I am not sure whether the destination IP address is the internal address (152.128.128.1) of our oracle server or the external ip (210.160.52.26) of our network. It has to be the internal address, right?
Also, what port should I allow the access on.

Can I use IP PassThrough to allow access?

A copy of the GBAdmin software can be obtained from here

For your information, we have two aliases created already
Alias1 ---> 210.160.52.27
Alias2 ---> 210.160.52.28
And these inbound tunnels exist already
TCP - Alias1,port 10000 to 152.128.128.1,port 10000
UDP - Alias1,port 10000 to 152.128.128.1,port 10000
<ALL) - Alias2, port 0 to 152.128.128.200, port 0 and so on..

Please let me know how to configure this.
I would really appreciate any help! Thanks
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top