Firewall and Multiple IP Addresses

Firewall and Multiple IP Addresses

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Firewall and Multiple IP Addresses RattMice 06-21-2005
Posted by on June 21, 2005, 4:21 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I am seeking advice on the following configuration. We currently have
4 domains that are hosted by a 3rd party ISP (http, email, ftp). This
works very well from the perspective of monthly service cost, speed,
backups, etc. However, we are now forced to host these on our own
servers.

Exchange Server 6.5 will be the email server (please don't beat up on
that as it wasn't my decision). HTTP will be on linux with apache
httpd and tomcat. Our current firewall is a WatchGaurd SOHO 6. Our
immediate upstream ISP has given us 3 static IP addresses.

Right now I have configured Exchange to accept email for all domains
but only 1 domain has the MX records pointing to our server; all others
are still being hosted. Email is being delivered to the Exchange
Server so the simplest case does work.

Here are my questions:

1) Will the SOHO 6 work for multiple IP addresses?
2) If so, does each domain need its own unique IP address?
3) If I want to route traffic from domain1.com to internal-server1 and
traffice from domain2.com to internal-server2, must the IP addresses be
unique or can the SOHO 6 route based on domain? Maybe that should just
be left to apache httpd?

If we need to change our firewall, then please make any suggestions.
Thank you for any tips and advice!

-Matt



Posted by Leythos on June 22, 2005, 3:27 am
If you were  Registered and logged in, you could reply and use other advanced thread options
RattMice@gmail.com says...
> I am seeking advice on the following configuration. We currently have
> 4 domains that are hosted by a 3rd party ISP (http, email, ftp). This
> works very well from the perspective of monthly service cost, speed,
> backups, etc. However, we are now forced to host these on our own
> servers.
>
> Exchange Server 6.5 will be the email server (please don't beat up on
> that as it wasn't my decision). HTTP will be on linux with apache
> httpd and tomcat. Our current firewall is a WatchGaurd SOHO 6. Our
> immediate upstream ISP has given us 3 static IP addresses.

I'm not going to beat you up for 6.5, but you need to be using 2000 or
2003 in order to get support and security updates.

> Right now I have configured Exchange to accept email for all domains
> but only 1 domain has the MX records pointing to our server; all others
> are still being hosted. Email is being delivered to the Exchange
> Server so the simplest case does work.

You need to setup user accounts on the server, then recipient policy for
each domain, then setup aliases for each user so that they have an
address in the public domain names. Make sure you set one of the public
names as the primary.

> Here are my questions:
>
> 1) Will the SOHO 6 work for multiple IP addresses?

Yes, you just need to add them to the External Interface.

> 2) If so, does each domain need its own unique IP address?

No, each inbound SMTP, as long as it goes to the same server that all
the domains reside on can use the same IP for MX and other.

> 3) If I want to route traffic from domain1.com to internal-server1 and
> traffice from domain2.com to internal-server2, must the IP addresses be
> unique or can the SOHO 6 route based on domain? Maybe that should just
> be left to apache httpd?

I have domain1.com and domain2.com with MX records that point to
mail.domain1.com and mail.domain2.com and both mail have A records that
have the same IP address.

As long as you setup exchange to handle the domains on the IP you
forward inbound to the server you can have 100+ domains on the same
exchange server (recipient policy domains)

> If we need to change our firewall, then please make any suggestions.
> Thank you for any tips and advice!

Until you max out the WG for performance reasons, and being that they
are limited to X internal IP Addresses based on your license, you can
use it forever.

While the 6 makes a nice SMALL firewall, you should look into getting a
700x so that you can filter email attachents, http sessions, etc....

--
--
spamfree999@rrohio.com
(Remove 999 to reply to me)


Similar ThreadsPosted
Route Multiple Internet IP addresses to internal web server.. Need help.. January 9, 2006, 12:50 pm
Multiple PCAnywhere behind firewall December 21, 2004, 10:23 am
Firewall for XP PC with multiple users September 18, 2005, 12:50 am
Firewall with multiple "red" interfaces March 30, 2006, 6:29 am
win 2003 pop server + multiple domains behind a firewall March 7, 2005, 7:10 am
Multiple LANs: Firewall advice required. July 13, 2005, 3:16 am
Does Firewall-1 Store Ethernet Addresses? January 11, 2007, 1:43 am
Cisco PIX and multiple VPN September 27, 2005, 12:36 pm
Multiple IPs on Sonicwall TZ 170 May 2, 2006, 1:30 am
multiple office vpn question December 21, 2004, 10:19 pm

The site map in XML format XML site map

Contact Us | Privacy Policy