LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 01-25-2008, 06:08 AM   #1
grant-skywalker
Member
 
Registered: Jul 2005
Location: Jakarta / Kuala Lumpur
Distribution: Slackware, Debian, Ubuntu, Centos
Posts: 40

Rep: Reputation: 15
Angry Weird firewall migration issue


Hi All,

I am facing a weird case while doing some migration on my firewall (pfSense), i do not know if this should be on firewall or networking.

internet
|
|
switch (3com) manageable switch
| |
| |
| |
server1(public ip) [firewall (public ip)]

This is my initial scenario, due to i have lots of servers but they are not consolidating, maintaining all the firewall rules for each of the servers is a nightmare for my SAs. So, we decided to migrate all the servers (which uses public ip) to the back of the firewall. Making it look like :

internet
|
|
firewall(public ip)
|(private ip)
|
|
switch(3com) manageable switch
|
|
|
server1(private ip)

From the diagram 1 migrating to diagram 2, the only thing i need to do is to change the server1's ip address/dns/gateway from the public ip to private ip, then in my firewall, i'll use 1:1 mapping and put the original public ip of the server to firewall (simple as that).

The problem comes :-

When i change my server1 to use private ip (i can ping the firewall private ip gateway and other private ip servers) but i can't ping outside (can ping google, but only resolving its ip but cannot reach outside).

At the same time, my colleague from office cannot ping/ssh in to my server1(which has switched to private ip).

But, if we ssh in to other server(also using private ip) and jump in to server1, it can. Just from public ip, it can't.

One more hint, few hours later (around 4 hours), outside can use public ip to ping/ssh and so as the server1 can reach outside world.

Well, has anyone come across this case?? Did i miss anything?? This is quite critical and i'm not able to provide a solid solution to solve this. These servers are production servers, i can't afford to 'down' it for 4 hours till outside world can reach it again.

regards,
GS

Last edited by grant-skywalker; 01-25-2008 at 06:13 AM. Reason: the diagram not correct
 
Old 01-25-2008, 09:19 AM   #2
iradix
LQ Newbie
 
Registered: Jan 2008
Posts: 4

Rep: Reputation: 0
What do your iptables rules look like on the firewall? Do you have forwarding enabled? Everything set up correctly in your routing table?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Weird GRUB Issue. Abomb Linux - Software 6 11-24-2006 09:02 PM
Weird issue with -current... Aeiri Slackware 2 07-28-2005 10:58 PM
a weird issue about which jiawj Red Hat 2 04-26-2005 09:06 AM
Linux 7 to 9 namespace migration issue er13b6ac Linux - Software 1 09-09-2003 05:27 AM
weird firewall problems andrew001 Linux - Networking 7 12-30-2002 12:47 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 09:30 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration