• April 25, 2024, 09:01:37 PM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: sat wan1 dmz http  (Read 5210 times)

perech

  • Level 1 Member
  • *
  • Posts: 1
sat wan1 dmz http
« on: April 03, 2013, 10:59:58 AM »

Thanks to all,

how do it?

I have this rules





but when I connect to the wan port this message appear on log

Date      
2013-04-03
12:12:48   

Severity   
Warning   

Category/ID
RULE
6000051   

Rule   
Default_Rule   

Proto   
TCP   

Src/DstIf   
wan1
   
Src/DstIP   
163.247.80.20

Src/DstPort
201.187.97.202   42648
80   

Event/Action
Encuesta
drop
ipdatalen=40 tcphdrlen=40 syn=1

help please
Brother, thanks the peace of Christ for you
« Last Edit: April 03, 2013, 11:48:18 AM by perech »
Logged

lucifer-tas

  • Level 1 Member
  • *
  • Posts: 6
Re: sat wan1 dmz http
« Reply #1 on: April 07, 2013, 01:35:08 AM »

I'm no expert but I might be able to help:
Remember to save your config so that you can undo the changes if this ends up not working.
If someone else like chechito or danilovav provide an answer, trust their answer more than mine because they know a lot more than me.


Firstly, in Objects -> Address Book -> InterfaceAddresses, define the private and public IP addresses of the server on the DMZ which you're trying to connect to.
For example:
    http-wan-ip = 192.168.1.100
    http-dmz-ip = 10.1.1.1

Change 192.168.1.100 above to an ip address on your wan network which is not already in use.
Change 10.1.1.1 to the ip address of the server on the dmz that you want to connect to.

Now in servicios_dmz, change the SAT rule to these settings (change the ip addresses below to match your network):
    Name: SAT_HTTP_TO_DMZ
    Action: SAT
    Service: HTTP-ALL
    Schedule: (none)
    Source interface: any
    Source network: all-nets
    Destination interface: wan
    Destination network: http-wan-ip

Then in the SAT tab of the SAT_HTTP_TO_DMZ, enter:
   Translate the: destination ip address
   To new IP address: http-dmz-ip

Now set the NAT_LAN rule settings to:
    Name: NAT_DMZ
    Action: NAT
    Service: HTTP_ALL
    Schedule: (none)
    Source interface: any
    Source network: all-nets
    Destination interface: wan
    Destination network: http-wan-ip

You shouldn't need the Allow rule because of the NAT rule which automatically allows but you could leave it there for the moment.

Now add an ARP Publish rule under Objects -> Interfaces -> ARP:
    Mode: Publish
    Interface: wan
    IP address: http-public-ip
    MAC: 00-00-00-00-00-00



The settings above are for a static wan ip. If you're using a dynamic wan ip, then change the destination interface for the SAT and NAT rules to "core" and change the destination network for the SAT and NAT rules to the dynamic ip address of the wan network (PPPoE-interface-ip).

« Last Edit: April 07, 2013, 01:46:33 AM by lucifer-tas »
Logged

danilovav

  • Level 4 Member
  • ****
  • Posts: 424
  • Alexandr Danilov
Re: sat wan1 dmz http
« Reply #2 on: April 15, 2013, 09:47:11 PM »

Please show your Status > Routes page
Logged
BR, Alexandr Danilov

sergiomnt

  • Level 1 Member
  • *
  • Posts: 13
Re: sat wan1 dmz http
« Reply #3 on: September 06, 2013, 11:56:25 AM »

Hello,

What is the model of your Firewall, sends the backup settings and configure your topology that for you.

Thank you.
Sérgio de Souza
sergio@masternet.com.br
Logged