cannot access webserver

Hi,

I hve a problem connecting from external to our corporate webserver. The web server is configured as DMZ and internally all staff can access but external cannot access. What did i miss ? is it at the checkpoint f/w configuration or the webserver network IP config ? pl provide advise.

thanks

Reply to
sg_s123
Loading thread data ...

Giving information about your network topology and firewall configuration. Your problem is most likely caused by wrong/missing firewall rules.

cu

59cobalt
Reply to
Ansgar -59cobalt- Wiechers

On 8 Jun 2006 13:55:06 GMT, Ansgar -59cobalt- Wiechers spoketh

wow. Amazing powers of observation...

Lars M. Hansen

formatting link
'badnews' with 'news' in e-mail address)

Reply to
Lars M. Hansen

On 8 Jun 2006 04:58:04 -0700, sg snipped-for-privacy@yahoo.com.sg spoketh

There are many things that could have gone wrong:

  1. No DNS record on external DNS server

  1. Incorrect DNS record on external DNS server.

  2. No rule on firewall to allow traffic from the outside to the DMZ web server.

  1. Incorrect rule on firewall for web access..

  2. Mismatch between virtual webserver name and (external) dns name

  1. Web server does not accept connections from external address space.

  2. Screening router blocking access.

  1. Error in routing table on web server (unlikely but possible)

  2. Firewall on web server blocks access from external addresses (note: this is different from #6, where the actual web service is denying access)

Lars M. Hansen

formatting link
'badnews' with 'news' in e-mail address)

Reply to
Lars M. Hansen

thanks all. Will look into it.

Lars M. Hansen wrote:

Reply to
sg_s123

i have done some research of existing config.I t seems that the webserver is pointing to the gateway (router) but the router had recently remove and we are on 4m link using MUX. the service provider gave 2 dns ip addr recently.

what i will be doing next is to

  1. change webserver preferred DNS and alternate DNS
  2. amend the checkpoint f/w rule webserver NAT that previously point to the router
  3. amend the netowrk properties DNS IP within the firewall DMZ and external config right ? 4. Btw, should i amend the DNS server ip config also ?
  4. is it true that the DNS will up 8 to 16 hours to refresh the cache b4 anyone can access the webserver externally ?

pl provide advise.. thanks

sg snipped-for-privacy@yahoo.com.sg wrote:

Reply to
sg_s123

What do you expect from doing that? What Lars meant was that you should check the records on your external DNS server(s) to make sure the name resolves to the correct address.

cu

59cobalt
Reply to
Ansgar -59cobalt- Wiechers

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.