SonicWALL 2040 + DMZ = Email/Web/FTP access

SonicWALL 2040 + DMZ = Email/Web/FTP access

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
SonicWALL 2040 + DMZ = Email/Web/FTP access Oldglory 04-04-2006
Posted by Oldglory on April 4, 2006, 1:35 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello,

I have a question about using a DMZ and setting up Email, FTP and Web
access. Before I get into it, I think I should explain our situation.
We currently have a Linux based web/email/ftp server that has a
firewall running on it. Unfortunately this box is outside the corporate
HW firewall (exposed to the Internet). Our corporate firewall handles a
DSL connection for Internet access and the web/email/ftp server handles
a wireless Internet connection (static IP). We currently can access the
web/email/ftp server remotely from intranet.companyname.com (web),
mail.companyname.com (mail), ftp.companyname.com (ftp) or the static IP
address. I recently got approved for a SonicWALL 2040 appliance that
supports two WAN connections (both our wireless and DSL Internet
connections). I like this because it centralizes the Internet
connections and it has fault tolerance. I then want to put our
web/email/ftp server in the DMZ of the SonicWALL appliance.

Question: Will users still be able to access the web/email/ftp server
internally/externally from intranet.companyname.com (web),
mail.companyname.com (mail), ftp.companyname.com (ftp) or the static IP
address? If so, how does that work? If not, how do I grant them access?

Thanks


Posted by Leythos on April 4, 2006, 4:00 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
mike.cocker@hotmail.com says...
> Question: Will users still be able to access the web/email/ftp server
> internally/externally from intranet.companyname.com (web),
> mail.companyname.com (mail), ftp.companyname.com (ftp) or the static IP
> address? If so, how does that work? If not, how do I grant them access?

If your DNS resolves to the proper IP Address then they should be able
to reach it.

So, if you have the server on a 192 scheme, and you are on a 192 scheme,
then you need DNS records for the public names on your internal DNS
server that point to the 192 addresses of the services. You would keep
the public IP DNS for people outside the local network and just forward
the ports inbound to the services IP address.

So, if the server was at 192.168.10.10 on the LAN and your PUBLIC IP was
244.12.12.12 you would need the following:

Public DNS A record 244.12.12.12 intranet.companyname.com
Public DNS A record 244.12.12.12 mail.companyname.com
Public DNS A record 244.12.12.12 ftp.companyname.com

PRIVATE DNS A record 192.168.10.10 intranet.companyname.com
PRIVATE DNS A record 192.168.10.10 mail.companyname.com
PRIVATE DNS A record 192.168.10.10 ftp.companyname.com

Your internal network clients should point to your internal DNS server
so that they resolve the internal IP's as defined.

Some devices allow DNS loopback, but not all, in that case you would not
need the Private DNS entries.



--

spam999free@rrohio.com
remove 999 in order to email me

Similar ThreadsPosted
SonicWall PRO 2040 Standard VPN November 10, 2006, 9:44 am
Sonicwall Pro 2040 and DNS issue March 1, 2007, 11:42 am
Sonicwall Pro 2040 and LinkSys BEFVP41 November 7, 2004, 9:30 pm
IPSEC Replay on Sonicwall 2040 March 16, 2006, 7:22 pm
Sonicwall 2040 can't block MSN Messenger 4.7 September 7, 2006, 4:38 am
SonicWall 2040 Login problem June 20, 2007, 9:57 am
Sonicwall 2040 series gateway for AV protection thoughts? Opinions? March 7, 2008, 12:17 pm
Sonicwall 2040 VPN Configuration - Connect to downstream router on remote side.... January 22, 2006, 3:33 pm
Sonicwall Wireless Access - VPN and Guest Access April 5, 2007, 10:45 am
SBS web access through Sonicwall April 26, 2006, 2:43 pm

The site map in XML format XML site map

Contact Us | Privacy Policy