Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Hello Let me try to explain my pro

Status
Not open for further replies.

Murugs

Technical User
Jun 24, 2002
549
US
Hello
Let me try to explain my problem here. Please suggest a god method or an alternate hardware for this problem.

In our office we are having a cable modem which connects to a microsoft router (4 port) and which inturn connects to 4 machines.The router runs a dhcp server and the IP addresses for the machines which are connected are in the range of 192.168.2.XX. One of the machines is a windows 2000 server which has the IP address 192.168.2.12.
The cable modem has the IP address of some 68.X.X.X which is static one.

The w2k server acts as a license server for an application. ( a piece of software which allows IP based licensing).
My laptop which I use it from home(I use dial up to connect to internet) also has this application but it needs license to run.
We were trying to access the license in the w2k server thru the internet from my home.
The router when installed came with pretty standard features like VPN etc..It also had this DMZ which said it allows some 2 way internet access. we were playing with that and when we entered our w2k server IP to be as a DMZ...surprise I was able to access the license from my home and run the application.
But the only problem was as soon as we enabled the DMZ on our server's IP address lot of window popped up and said your machine is hacked etc..we had to remove that DMZ on our server due to this reason. we felt our machines are now not secure. Now we need to find an alternate way to do this so that I can access the license from home.
I guess something to do with router or some thing related to NAT or do we need to buy a new piece of hardware which will support our setup. experts pls advise.

regards
MP
 
Most basic routers have a port forwarding function. You should be able to forward the port the certificates run on to the server ip. That way you are not exposing the whole machine, just the one port.

-Ed
 
Thanks for the reply.
I got it working by using the port forwarding method.

My router port forwarding looks like this

inbound port ip adddress privateport
10 192.168.x.x 7788

the above does not work ..other way is to give a range in inbound port which works but whatever range is given in inbound port is explicitly transfered to the private port.
i.e If we specify a range we do not have any control over the private port field tab.

inbound port ip adddress privateport
1-8000 192.168.x.x 1-8000.

The above setup works but increases the risk that all ports are open. How to open only a particular port. How to identify a incoming port.

Hope I have explained my question properly.



 
You will need to find out what the specific port(s) are that the application liscencing uses. Unfortunately, I do not know what those are. Then you will need to forward those specific ports to the internal addresses.
IE: if the port is 7788

inbound port ip adddress privateport
7788 192.168.x.x 7788

There may be more than one port to allow but it should work when you are finished. This way all the other ports can stay blocked.

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top