This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

External access from DMZ

Hi,

I have a few servers in DMZ, all of them have static-ip and geateway, we haven't configured DNS since we dont want these servers to resolve names.

We have a web server in wan side but when we try to access it from DMZ the log says Default Drop. How can I resolve this?.

I have created a MASQ rule DMZ to WAN.

Also created firewal rule DMZ -> any service to WAN.

I have turned of all shields except firewall.



This thread was automatically locked due to age.
  • Hi,

    looks like the firewall rule is not matching.

    Is the subnet 192.168.20.xx your "WAN" subnet? If yes, you don't need MASQ because you can route between this subnets with the UTM.

    Please post a screenshot of your interfaces and the firewall rule. It will help us to help you.

     

    Jas

     

  • 192.168.2.x network is located within WAN-Subnet?

    please post the MASQ and Firewall-rule.

     


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

  • "I have created a MASQ rule DMZ to WAN."

    I don't understand how that relates to accessing the Internal network from the DMZ.

    "Also created firewal rule DMZ -> any service to WAN."

    Please insert a picture of this rule open in Edit.  Again, I don't understand how that relates to accessing the Internal network from the DMZ.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hello All,

    Thank you fro quick reply.

    What I wanted to do is, my server in DMZ must be able to access a dedicated server in WAN side.

    Simply speaking 10.10.10.15->any port-> 192.168.20.254-> port 80

    My WAN subnet = 192.168.20.0/24

    My Internal Subnet = 192.168.1.0/24

    My DMZ Subnet = 10.10.10.0/24

     

  • DMZ-metas is 10.10.10.15 ?

     

    .. your first post shows 10.10.10.4 dropped.


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

  • As Dirk points out below, I wasn't "seeing" the topology.  Jacob's #15 is correct as written.

    Firewall rule 15 should have a Traffic Selector of 'DMZ-metas -> Any -> Internet'.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi Jenson,

    You need a Full NAT to reach the server. Can you configure a Full NAT policy referring the suggested KBA by rsenio in the first answer to this question. Show us the screenshots after configuring it.

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • Hi Bob,

    the destination server (192.168.20.21) reside within Subnet "external (WAN) Network" (192.168.20.0/24) 

    So the destination of this rule should be OK ... i think ... i am false?

     


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

  • Hi sachingurung,

    I don#t understand why full-nat should be necessary.

    Can you give me some hints please?

    Thanks

     


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.