Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Multiple Servers with multiple DNS hosts and can't view them internally

Hello All,

Need some help with DNS host names for 3 different servers on my internet network.  Ideally, I would like to use just one DNS Host and not 3 separate Hosts.  Trying to use an external DNS name to resolve locally.  Sophos UTM Home 9.4.  I have rebooted the UTM once.

 **dns names, IP & ports are made up

I have created all 3 Hosts with NO-IP.com, DynDNS setup in the UTM and works perfectly.  I can view all of these devices outside of my network just fine.  But on my internal network, I can’t use the camera app to see the cameras using cameras.com:123  OR Firefox/IE/Chrome  for http://web.cameras.com:789.

However, auto.cameras.com:465  does work locally.

Also, I can use the camera app 192.168.1.200:123  And Firefox/IE/Chrome  http://192.168.1.150:456  And http://192.168.1.130:789

Would like my mobile apps/websites and local apps/websites to use the external hostname whether I’m home or away.

 

Cameras 192.168.1.200:123

In Network Hosts – DNS Hostname set to cameras.com  & Any Interface - Created a DNS Host cameras.com and set to Any Interface

Home Automation  192.168.1.150:456

In Network Hosts – DNS Hostname set to auto.cameras.com  & Any Interface - Created a DNS Host auto.cameras.com and set to Any Interface

Web Server  192.168.1.130:789

In Network Hosts – DNS Hostname set to web.cameras.com  & Any Interface - Created a DNS Host web.cameras.com and set to Any Interface

 

DNAT Rule:

For Traffic – Any

Using Service: Home Automation (TCP/UDP)

Going To – External WAN Address

Change the destination port: Home Automation physical device IP address

Checked Automatic Firewall Rule

 

DNAT Rule:

For Traffic – Any

Using Service: Web (TCP)

Going To – External WAN Address

Change the destination port: Web server physical device IP address

Checked Automatic Firewall Rule

 

(Same rule set for the cameras...)

 

Any thoughts?

 

Thanks for your time in reading this, I wouldn't post this if it wasn't important and have spent an afternoon trying all kinds of different items.



This thread was automatically locked due to age.
Parents
  • Follow up.  Been hard at this morning, since the web server is using a weird port number, dropped the DNAT rules just did a virtual/real web server.  Now I can visit the local domain name access using web.cameras.com:789 for my iPhone as well as LTE domain name working too.  Excited!

    I don't get what I'm missing for my cameras, they go across 6 different ports (mobile, desktop, backing up), should be TCP, but I have TCP/UDP set in the UTM.  I removed the DNS Hosts in network definitions.  Kept the DNS hostname in the Network Host definition.

    I believe but not sure.. DNAT add or tweak may fix it?  Inside the network then going outside and then back inside.  Hoping the UTM can see that I have the DNS setup so it just go straight to the internal IP.

    Removed all DNS Hosts (but kept the domain name in the Network Host for the DVR.

    Got it!

    Rule 3
     Rule type: Full NAT
     Traffic Selector: Internal (network)
     Using service: 17000,17001...
     Going to: External WAN Address
     Source translation: Internal Addresss (192.168.1.1)
     Destination translation: DVR


    Rule 4
     Rule type: DNAT
     Traffic from: ANY
     Using service: 17000, 17000
     Going to: External WAN Address
     Desintaion translation: DVR

Reply
  • Follow up.  Been hard at this morning, since the web server is using a weird port number, dropped the DNAT rules just did a virtual/real web server.  Now I can visit the local domain name access using web.cameras.com:789 for my iPhone as well as LTE domain name working too.  Excited!

    I don't get what I'm missing for my cameras, they go across 6 different ports (mobile, desktop, backing up), should be TCP, but I have TCP/UDP set in the UTM.  I removed the DNS Hosts in network definitions.  Kept the DNS hostname in the Network Host definition.

    I believe but not sure.. DNAT add or tweak may fix it?  Inside the network then going outside and then back inside.  Hoping the UTM can see that I have the DNS setup so it just go straight to the internal IP.

    Removed all DNS Hosts (but kept the domain name in the Network Host for the DVR.

    Got it!

    Rule 3
     Rule type: Full NAT
     Traffic Selector: Internal (network)
     Using service: 17000,17001...
     Going to: External WAN Address
     Source translation: Internal Addresss (192.168.1.1)
     Destination translation: DVR


    Rule 4
     Rule type: DNAT
     Traffic from: ANY
     Using service: 17000, 17000
     Going to: External WAN Address
     Desintaion translation: DVR

Children
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?