Domains Literals Fail Behind NAT'd Firewall.. Workarounds??

To the Ipswitch web site

Ipswitch Forums
Home      Members   Calendar   Who's On
Welcome Guest ( Login | Register )
      



Domains Literals Fail Behind NAT'd Firewall.. Workarounds??Expand / Collapse
Author
Message
Posted 8/10/2004 1:18:41 PM
Forum Newbie

Forum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum Newbie

Group: Forum Members
Last Login: 8/17/2004 8:44:00 AM
Posts: 3, Visits: 1

I have 15 Domains behind a Firewall, All Domains on the Imail server are using "Private" IP's which have a 1:1 Nat to a Public IP, However none of the domains will except domain literals, I even tried adding [xxx.xxx.xxx.xxx] and/or xxx.xxx.xxx.xxx as an alias for the given domain, and still does not except a ip literal from outside the net, however will except if i use the PrivateIP as the literal for the said domain.

 

Any Ideas?

 

Post #697
Posted 8/11/2004 12:47:29 AM
Time Traveler

Time TravelerTime TravelerTime TravelerTime TravelerTime TravelerTime TravelerTime TravelerTime Traveler

Group: Forum Members
Last Login: 6/15/2005 1:07:00 AM
Posts: 217, Visits: 1

You have to bind the public NAT address as a secondary address on the NIC.

Yes, it sounds kludgy, but it works.  At the network level, your mailserver should never need to route to its own public NAT address through the firewall, so the fact that you're "short-circuiting" the route by steering it to localhost should be okay. 

--Sandy



------------------------------------
Sanford Whiteman, Chief Technologist
Broadleaf Systems, a division of
Cypress Integrated Systems, Inc.

Defuse Dictionary Attacks: Turn Remote Mailboxes into Aliases on your IMail MX!
  http://www.imprimia.com/products/software/freeutils/ldap2aliases/download/release/

Post #707
Posted 8/17/2004 8:55:05 AM
Forum Newbie

Forum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum Newbie

Group: Forum Members
Last Login: 8/17/2004 8:44:00 AM
Posts: 3, Visits: 1

This is the only way to do this???? Why can't IpSwitch just fix imail to accept [0.0.0.0] as an alias for said domain.  

Post #805
Posted 8/17/2004 7:01:04 PM
Time Traveler

Time TravelerTime TravelerTime TravelerTime TravelerTime TravelerTime TravelerTime TravelerTime Traveler

Group: Forum Members
Last Login: 6/15/2005 1:07:00 AM
Posts: 217, Visits: 1

If they really accepted [0.0.0.0] as local, that would accept all domain literals locally, which completely breaks domain literals.

Not really sure what the big deal is with adding a secondary IP, since that's exactly how you want the box to behave.  Remember that NAT is not something that most IP-aware applications can deal with easily (cf. VPNs, et al.).

--Sandy



------------------------------------
Sanford Whiteman, Chief Technologist
Broadleaf Systems, a division of
Cypress Integrated Systems, Inc.

Defuse Dictionary Attacks: Turn Remote Mailboxes into Aliases on your IMail MX!
  http://www.imprimia.com/products/software/freeutils/ldap2aliases/download/release/

Post #823
« Prev Topic | Next Topic »


Reading This TopicExpand / Collapse
Active Users: 0 (0 guests, 0 members, 0 anonymous members)
No members currently viewing this topic.
Forum Moderators: Dave, Mark Singh, kevin r gillis, Jason Benton, Brandon Felger, Ben Henderson, Tripp Allen, Will Sansbury, Hush, FTPplanet.com, Hugh Garber, WUP-PM, Tom Lewis, mmulryan@ipswitch.com, mswimm, Brad Senter

PermissionsExpand / Collapse

All times are GMT -5:00, Time now is 4:26pm

Powered By InstantForum.NET v4.1.4 © 2008
Execution: 0.094. 10 queries. Compression Enabled.