LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 02-11-2024, 07:44 AM   #1
crana
LQ Newbie
 
Registered: Feb 2024
Posts: 3

Rep: Reputation: 0
Need help with IpCop


Hi!

I'm hoping somebody can help me.

I'm having trouble configuring IpCop.
From the web server I have in the DMZ, I can't ping IpCop or the red interface and according to the official IpCop page, it should be open by default. That's my main problem right now.

From IpCop, I have access to the internet, to the internal network, and to the DMZ, and I can ping without any problems.
From the internal network, I also have internet access.

I'm doing everything in VirtualBox.

The red interface is set to NAT.


Any help would be appreciated.

Here is a link with an image of my ipcop network setup.

https://ucd05aaa92ca5696e0f3a0b1be8f...58uzxlpw/file#
 
Old 02-11-2024, 08:42 AM   #2
michaelk
Moderator
 
Registered: Aug 2002
Posts: 25,783

Rep: Reputation: 5936Reputation: 5936Reputation: 5936Reputation: 5936Reputation: 5936Reputation: 5936Reputation: 5936Reputation: 5936Reputation: 5936Reputation: 5936Reputation: 5936
You will not be able to ping the red interface from your home LAN if using NAT. VirtualBox NAT is a basic router in itself. Shutdown IpCop and switch the red network adapter from NAT to Bridged.
 
1 members found this post helpful.
Old 02-11-2024, 10:41 AM   #3
crana
LQ Newbie
 
Registered: Feb 2024
Posts: 3

Original Poster
Rep: Reputation: 0
Thanks a lot!

I changed the red network adapter from NAT to Bridged. I used to have it set to Bridged, but someone had told me to switch it to NAT.

I still have the same problem in that from the server in the DMZ, I can't ping the Orange or Red adapters, but I can ping my home's Router and browse the internet just fine.
I imagine I should be able to ping the Orange and Red adapters from within the DMZ, since I can ping them from the client in the Green zone (?)

So while I can browse the internet from the DMZ, I worry something might still be wrong as I can't ping the Adapters.

The main issue tho, is that I can't access the web server in the DMZ from my home network.

I made a port forwarding rule in IPCop, to forward all traffic on port 80 to the IP of the server in the DMZ, but doesn't seem to be working.

The port forwarding rule looks like this:
Net Iface: Any | Source: Any:80 | >> | Net Iface: ORANGE | Internal Destination: 100.99.100.2:http (the DMZ server's IP)
 
Old 02-11-2024, 11:21 AM   #4
michaelk
Moderator
 
Registered: Aug 2002
Posts: 25,783

Rep: Reputation: 5936Reputation: 5936Reputation: 5936Reputation: 5936Reputation: 5936Reputation: 5936Reputation: 5936Reputation: 5936Reputation: 5936Reputation: 5936Reputation: 5936
I am not all that familiar with ipcop.
I don't know if there are any rules to drop ping requests from that zone. If so then pings do not work but regular traffic does and maybe dependent on how the pinholes if any are configured. If you can not access the DMZ from your home network the port forwarding rule isn't correct. Be sure you selected TCP and not UDP.


https://www.ipcop.org/2-0-0/en/admin...l-traffic.html

By the way ipcop is discontinued. I use PFsense but there are others like untangle, IPfire (fork of IPcop), OPNsense (a fork of PFsense) that would be better to run.

Last edited by michaelk; 02-11-2024 at 12:32 PM.
 
1 members found this post helpful.
Old 02-11-2024, 03:09 PM   #5
crana
LQ Newbie
 
Registered: Feb 2024
Posts: 3

Original Poster
Rep: Reputation: 0
I was able to figure out what I was doing wrong.

Turns out I was trying to access the DMZ server by using its IP, while I had to use the IP of the red interface.
Doing that, the port forwarding rule correctly forwards the traffic to the server!

Thanks again for your help!

I would switch firewalls, but it's for an exercise and I'm stuck with IpCop for now.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
can ping red side of ipcop firewall but cannot reach internet. I can see ipcop in my aofwnb2d Linux - Newbie 3 12-17-2011 07:47 PM
Need IPCop to IpCop VPN assistance Freddde Linux - Networking 1 09-15-2005 02:28 PM
Need help with IPCOP! SlipAway172 Linux - General 2 01-24-2005 04:49 PM
IPCop to IPCop VPN... furrie Linux - Networking 1 11-04-2003 12:40 PM
need help setting up IPcop-DMZ > webserver greg@athena Linux - Security 1 10-04-2002 07:09 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 02:31 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration