Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Enabling access to a resource from out side

Status
Not open for further replies.

atansori1

Technical User
Jan 24, 2010
1
SA
Hi,
My scenario is as follows.

I have a sonicwall pro 3060 with IOS 3.0 Enhanced.

1. My DSL modem is connected to the Sonicwall pro. The modem is assigned with a static IP by the ISP (eg : 213.166.xxx.xxx)
2.The LAN interface of the modem got assigned by another local IP (eg: 10.1.1.2)
3.I am connecting this modem to the WAN interface of the Sonicwall & assigned the following IP to the WAN interface (10.1.1.3)
4.The Lan interface of the Sonicwall has the following IP 172.16.14.1
5.All my servers & switches are having the same range of IP's (172.16.14.xxx)
Now my Question is i want to create a rule, it should allow any user from the internet to telnet to my switch. Only telnet session should be allowed. So when they type the Static IP of the modem(i.e 213.166.xxx.xxx) it should be directly forwarded to the switch.

Any help on this issue is highly appretiated.
 
What you are speaking of is pretty simple. In the Sonicwall world, I think it is called Public Server Wizard. You can simply run the Wizard, tell it what service you want to allow (telnet TCP port 23), on the next page fill out the switch name and IP address, then on the next page be sure the public IP address of the Sonicwall is listed and apply the changes. Basically, this creates a NAT rule and Firewall rule to translate and allow the traffic into the network. There could be security concerns since this opens the switch up to the entire world, so be sure you use a strong password!

Cheers,
Anony Moose
 
To avoid a double nat situation it would be best to set your dsl modem as a bridge. That way your Sonicwall has the public ip. Then from there you can follow the steps brainblurb spoke of and create a port forward. Otherwise the setup you have now you would also have to do a port forward in the dsl router and creates the double nat situation and sometimes certain applications don't handle it well.

Network+ Inet+ MCP MCSA 2k3
 
If you need help bridging the dsl modem provide the brand and model. Then we can go from there.

Network+ Inet+ MCP MCSA 2k3
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top