This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

internal access to wan IP (dynamic DNS)

i'm using Dynamic DNS , and i configure the policy to access my servers by RDP from outside, and it's working fine,

but i can't access it internal by dynamic dns or wan ip,  can any one help please ?



This thread was automatically locked due to age.
Parents
  • Khaled,

    can you share some screenshot of your configuration?

    Thanks.

  • i can access everything from outside, only from internal i can't access using the wan ip or dynamic dns 

  • Khaled,

    this is correct. You should use internal IP to access internal host. However if you put inside the BARs LAN on Source zone either, it will allows you to access.

    As I said, use internal Ip to access internal hosts.

  • Hi Luk,

    Currently i use Sophos XG installed on Mini PC. Using Sophos DynDNS

    I'm able to access user portal to download SSL VPN Client from outside network using https://bethelsophosxg.myfirewall.co:443

    but im unable to access Admin portal via https://bethelsophosxg.myfirewall.co:4444 

    Have enabled WAN and LAN access under "Device Access"

    Atm only way to access Admin portal is to have connected to VPN first ( when on external network ) and then access via LAN port

    Is there anyway to access Admin portal without having to be connected to VPN

    Appreciate any help

    Please refer below for Device Access config

  • Hi Ruka,

    you do not need DNS on the WAN, that means you are providing a DNS for all internet users.

    Have you configured the admin access within the GUI -> Admin -> admin settings?

     

    Ian

  • Morning Ian,

    Have changed the settings as below , please let know if anything else needs to checked or unchecked to keep it more secure.

    Yes, i had used GUI for configuring Admin Access , initial Admin password was given when during initial OS install , after which i have changed it via GUI

     

     

    Appreciate your help

    Regards

    Raju George

  • Hi Ruka,

    if you want to access your XG internally using the FQDN you will need to create a DNS host entry in the network tab using the FQDN but using the internal address and do not tick the publish on wan box.

    Ian

  • Hi Ian,

     

    Thanks for your reply , i had this configured initially but Publish on WAN was ticked , please advise what are the differences on having ticket and unticked ( have unticked it as per advise )

    Also im wanting to access this FQDN while im on different network , for eg : at Office ,internally it works fine  :443 for user portal but not :4444 for Admin portal , need to use https://192.168.1.150:4444 when on internal network

    Also should i be using Port IP or NAT'ed Public IP , please refer to below screen

     

     

    Appreciate your assistance as always

    Regards


    Raju

Reply
  • Hi Ian,

     

    Thanks for your reply , i had this configured initially but Publish on WAN was ticked , please advise what are the differences on having ticket and unticked ( have unticked it as per advise )

    Also im wanting to access this FQDN while im on different network , for eg : at Office ,internally it works fine  :443 for user portal but not :4444 for Admin portal , need to use https://192.168.1.150:4444 when on internal network

    Also should i be using Port IP or NAT'ed Public IP , please refer to below screen

     

     

    Appreciate your assistance as always

    Regards


    Raju

Children
  • Hi Ruka,

    if you tick advertising on WAN you are posting your internal address on the WAN, not advisable.

    The internal lookup should look a bit like this, part of the shot has been cutoff.

     

     

    When using the dynamic DNS you should be using your external interface and preferably with its FQDN and I assume you have registered it with the Sophos DNS?

     

    Ian

  • Hi Ian,

    Thanks for your reply ,when i ping FQDN which is registered with Sophos DynDNS i get public IP 14.201.88.67

    But when i try to access admin portal with :4444 i get below error

    Is this because Sophos DynDNS is a free service and works only to for accessing user portal 

     

     

    Appreciate your help

    Also just for curiosity , are you able to access your Admin portal from a different network

    Regards


    Raju

  • Hi Ruka,

    what do you mean admin portal?

    I have disabled my external access because it is a security risk, I use the Sophos CM if I want to access my XG which is free with 7 days of reports data stored.

    The Sophos DNS has no idea about what you are using the connection for, it provides an IP address for a requested URL if the URL is registered with the Sophos DNS.

    There is something wrong with your connection that is causing the XG not to respond on port 4444.

    Ian

  • Hi Ian,

    Thanks for your message , what i meant by admin portal is admin console ,please refer below

     

    Will try to change port 4444 to something else and test if that works

    Thanks for your help and apologies for the delay in replying

  • Hi,

    don't change the GUI port, try logging into eh XG GUI using the external IP address of your XG.

    Ian

  • Hi Ian,

    Thanks for your reply , tried external IP  , which is https://14.201.88.67:4444 

    Still no luck on port 4444 but 443 works fine for accessing User portal

    Accessing User portal works both on Chrome and Firefox

    On a side note , able to access Admin console when connected to either Sophos Connect or SSL VPN but by using Port 1 or Port 3 LAN Interface IPs

    Not sure what else to be looked at

    As always appreciate your time and effort

    Regards


    Raj

  • Hi Ruka,

    did you try usingg the external access from a different site?

    Ian

  • I would suspect that port 4444 is being blocked by TPG.

    Ian

  • Hi Ian,

    Thanks for your reply, tried using my mobile phone

    same results , able to access user portal but no luck with accessing admin portal

    tried both external IP and FQDN with :4444 

    Without port number takes me directly to user portal thou

    Appreciate your cooperation

    Thanks

    Raju

  • Thanks Ian

    I too feel that now, would changing the port number on Device Access the only thing that needs to be done or is there any other place we need to update port number

    Thanks

    Raju