• February 24, 2025, 01:19:10 AM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: DFL-800 - still having difficulties to understand the logic - if there is one  (Read 4570 times)

djurhuus

  • Level 1 Member
  • *
  • Posts: 2

I have owned this thing for a couple of years and I still think its as difficult as Cisco to setup - it's a petty good hardware though.

The difficulties:

DFL-800
Firmware Version:    2.27.02.11-14417 - Aug 23 2010

Public IP:
80.xxx.xxx.xxx

LAN net:
192.168.1.0

Mac OS X 10.6 server as dhcp, dns, web (webmultiple websites), image, wiki server etc.:
192.168.1.2

Mail server as SMTP, imap, pop3, http/https webmail):
192.168.1.3

ISPConfig3 hosting server as web (webmultiple websites), mail (SMTP, imap, pop3, http/https webmail), dns:
192.168.1.4

My main problem is how to make the translation from one public IP to many private IP's especially on multiple webservers (three in all).
I can't seem to find the golden information/logic and make a working configuration that makes all three web servers visible from outside.
I can get it to work with one web server and one webmail server (by redirecting the port from 80 to 8080).


I have been using the traditional SAT (no DMZ) based on a service enabling port 80,8008,443,8443
any or wan1 > all-nets > core > wan1_external_ip + (SAT to the specified server)

And a corresponding allow rule and on the same service enabling port 80,8080,443,8443
any or wan1 > all-nets > core > wan1_external_ip

I have made this scenario for every web server.

When I do like this it seems like I only are directed to (can see from outside) one webserver!!!
What am I doing wrong or haven't understood after all these years and are tiered of using a lot of time reading on how to set it up - trying all sort of things and getting nowhere.

Do I need to use DMZ?
And if I have to use DMZ (like 10.0.0.0) how do I get i contact (route) from LAN with my Mac OS X server so it will distribute dhcp, work as dns and be able to roll out image?

Please enlighten me on this matter and on the DLF-800 logic.
« Last Edit: November 29, 2010, 07:37:46 AM by djurhuus »
Logged

djurhuus

  • Level 1 Member
  • *
  • Posts: 2

Nobody with a solution :o
Logged

Woodjitsu

  • Level 1 Member
  • *
  • Posts: 2

I am guessing you have 4 separate sets of rules for all that (ie one set of rules each for ports 80, 8080, 443 and 8443??

Have you tried turning on logging for those rules?  I have found this is the best way to find out where the traffic is ending up and why.
Logged

silver_surfer30

  • Level 3 Member
  • ***
  • Posts: 107

Hi first of all you need to modify the webui port access otherwise the NetDefendOS will capture all incoming access for http or https as a direct access to it.

you can do so in remote management/advanced settings

You also need to know that on a DFL-800 you have 4 interfaces. the wan1, wan2, DMZ and Lan.
But there is also an other interface call Core.

All the traffic goes through the core interface to be be inspected and all security mecanism will be done.

The Core interface owns all Interfaces IP. Thus all traffic from and to DFL will go through Core.

Lan-IP, dmz_ip, wan1_ip, wan2_ip belong to core.

If you go status/routes and check the show all routes box, then you will see the core interface.

hope that it will help.
Logged