How to DHCP Server with NO ROUTER on Server Admin panel field?

Hi all!
I'm having a little problem.
I have two completely different networks, with different purposes, one is 10.0.10.X and the other is 192.168.10.X. My networks is like this:
Internet------Wifi Router (192.168.10.250) -----iMacs AirPoirt (192.168.10.X)
MacPro (10.0.10.100)-----iMacs Ethernet (10.0.10.X)
Great, is so simple. So I had a DHCP server (Windows blerg) on the 10.0.10.X (NOT MAC OS X SERVER) and everything works perfect, since on the Windows DHCP Server I'm not forced to fill the router/gateway and leaving it blank makes the iMacs have just one router/gateway from the 192.168.10.X lease from the Wifi Router.
Now I'm planning to migrate the DHCP Service to the Mac OS X Server (Snow Leopard Server), I fiddled a bit and found that I can't use DHCP Server on Mac OS Server leaving router field blank and if I type ANYTHING, my iMacs will NOT access the internet through 192.162.10.X since now there's two gateways (from 10.0.10.X that Server Admin panel forced me to fill and from 192.168.10.X that HAS to have one gateway and it's the correct one).
I've tried to fill with the 192.168.10.X gateway but throws a warning saying that is not on the same subnet.
I really don't want to re-route or mix the traffic for many reasons.
So I ask, is there any possible way to NOT fill or bypass or do anything to make DHCP Server service from Mac OS X Server not have a gateway/router?
The only way I'm managing to do it now is to use manually entered IPs on the iMacs, but it's 10 iMacs and I guess for some services like netboot etc I need DHCP.
Cheers,

Lets assume that before you had computers with both Ethernet and WiFi connections, they were able to access the Internet via WiFi and talk amongst themselves via Ethernet. The Ethernet addresses were not (in theory) accessible from the WiFi network and hence not accessible from the Internet. Presumably you intended this for security reasons.
If so, you were completely mistaken. Even if you turned on a Software firewall on each of these iMacs to in theory block traffic going between the two networks you still have a potentially insecure setup. This is because traffic can reach the iMacs via WiFi. Once hypothetical malicious traffic has invaded an iMac via WiFi it can take control over the computer and within that computer reach out via its Ethernet port to other Ethernet computers.
The only way to ensure complete security is not to have any link between the two networks at all. If one of the computers is linked to both then you have a potential path for attacks to travel across.
So what are you really trying to do? If you want two totally separate networks with one having absolutely no link to the outside world then this is simple and is as follows.
NETWORK1 Internet------Wifi Router (192.168.10.250) -----iMacs AirPoirt (192.168.10.X)
NETWORK2 MacPro (10.0.10.100)-----different iMacs Ethernet (10.0.10.X) with WiFi turned off
You could define the default gateway for NETWORK2 as being the DHCP server itself. No computer on NETWORK2 would be able to access the Internet and hence it would be totally secure.
If however you want all computers to be able to access the Internet then you need a link between them. Are you merely wanting to segregate WiFi traffic as it might be insecure and evesdropped on? If so then the following is a better approach
                         WiFi clients (192.168.10.x)
Internet ----- AirPort Extreme (192.168.10.250) ------ Hardware FireWall does NAT (10.0.10.1) ---- MacPro (10.0.10.100) ---- iMacs via Ethernet (10.0.10.x)
The WiFi clients would not be able to directly access your 10.0.10.x network as they are blocked by the FireWall. However if you have say a Laptop that you want ot use on WiFi but still access your server on your internal secure LAN you would do this by having the server run the VPN server component. The WiFi client would then connect via the VPN server and this would ensure all the network traffic going over the WiFi is encrypted using industry standard IPSec encryption. In this second scenario the MacPro (presumably your server) would have the FireWall as the default gateway, and the FireWall would have the Internet router as its default gateway. You could set the Firewall to forward VPN traffic to the server or use the second Ethernet port on the server to accept VPN traffic on the 192.168.10.x LAN.
This is my own setup is something like
                        AirPort
                           |
Internet router --- Public IP range --- (WAN) FireWall (LAN) --- LAN Switch --- Server Port1 for normal traffic
                                                 |(DMZ)                                    |
                                                 +----------------------------- Server Port2 for VPN

Similar Messages

  • Replace a 2003 (not R2) File Server with a 2012R2 files server and preferably keep the same machine name and IP when finished

    I am wanting to replace a 2003 (not R2) File Server with a 2012R2 file server and preferably keep the same machine name and IP when finished.  For the moment I just need some "high level" guidance, little details can be worked out once I know
    which direction I will go.  I was considering that DFS might be a way to help get through the process although when finished the 2012R2 Files server will be by itself with no other file server planned at this time.  DFS can stay installed for maybe
    future purposes but clearly I wouldn't need the DFS Replication with only one machine.
    Here's a few details of the environment....
    1.  DC's are 2012R2 but it is still 2003 DFL because the old 2003 DCs are still present.  But likely they will be gone and the DFL elevated before I start on the File Server project
    2. Nearly all machines in the facility have a shortcut on the "All Users" Desktop that points to the existing old File Server.  Editing or replacing that shortcut would be a major pain,...hence why I want to keep the same machine name at least,
    and maybe the same IP if not too much trouble.  This way the existing shortcut would continue to work with the new 2012R2 File Server.  The UNC path represented in that shortcut is also configured into one or more of our major business applications,
    futher emphasizing the need to keep the UNC path the same throughout the process.
    3. The facility runs 24/7/365 but is "light" on weekends.  The political environment is such that there is little to no tolerance for any down time at all.
    4. Would DFS (based from the 2012R2 machine) be a good tool to get where I need to go?
    Thanks for any suggestions.
    Phillip Windell

    Hi Sharon,
    I've done some more reading and have a few new ideas to run past you....
    Yes regular DFS wouldn't help and the Namespace would still be different than how it was with just the old server. However I was thinking DFS Replication could replace the purpose of RoboCopy and it would keep the two locations "in sync" until I was ready
    to flip over to the new server.  DFS Rep can exist independently of a DFS Namespace, so a Namespace is not even needed. It needs a minimum of 2003R2 for the "later & better" DFS Rep but I believe 2003 can do an "in place" upgrade to 2003R2, so I would upgrade
    the old server to 2003R2 first.  As long as the DFS Rep on 2012R2 and 2003R2 will properly interact I think that will work.
    Thanks for the reg info on the Shares.  I'm debating if editing that would reg file would really be much better than manually creating the Shares on the new server while the DFS Replication was doing its job.  I'll probably export that Key as a
    safety move whether I use it or not.
    Once the DFS Rep is fully in sync and the Shares are in place on the new server, I figure I would then:
    1. Remove the DFS Replication Object (optionally remove DFS Services completely)
    2. Rename the old File Server to something else and set it to DHCP
    3. Rename the new File Server to the name I want to use and give it the IP the old server had.
    How does that sound?
    Phillip Windell

  • VPN Server with two router local network

    I just got a Mac Mini Server 2011 to set up as a home server. One of the main features I want to use is a VPN so I can access my files on my local network when I'm away from home. I live in Japan and I have a Japanese optical connection to the internet that runs through two boxes before I can use it in any form: some sort of modem, and a "gateway" which I literally just found out is also acting as a router and serving DHCP addresses. In addition, I have a 2TB Time Capsule that, until just recently, I had been using in the "Share a Public IP" mode because I didn't realize the gateway was also issuing DHCP addresses. I cannot simply plug my TC into the modem in place of the gateway - both are required to access the internet.
    Until today I had both routers using DHCP on the local networks they each created. Under that environment, I had finally configured Lion Server to file share (easy), manage network accounts (moderate), and serve Profile Manager (difficult). But despite my best efforts at mapping the ports on the Time Capsule, I just couldn't get the ports open using tools like canyouseeme.org, so the VPN was a no-go. That's when I realized the gateway could be a router too, so with some creative google searches, and extensive use of google translate, I was able to figure out how to open ports on the gateway. It does it pretty differently from the Time Capsule and other routers I've seen. It asks you define the host on the LAN (what i assume to be the target IP), the protocol (TCP vs. UDP), and then a range of ports for it to open. I plugged in the IP of the Time Capsule, opened all the UDP ports (since it was an option to just open all, and I figured 1) the TC would still protect my network and 2) it would just be a test), but I still couldn't see the ports as being open.
    So then I got desperate, and I switched the TC back to Bridge Mode, reconfigured the Server and my MBP (my client Mac) to the new IP addresses being served by the Japanese gateway, and tried again. I think I reconfigured the DNS settings in Server Admin properly to account for the change in IP, and then updated the services in Server.app, but now I can't even get to my server homepage (the apple placeholder page) using either its IP or its .private domain, and to make matters worse, I STILL can't seem to get the ports open (yes, I changed the port mapping to send it directly to the server IP as the target after the change).
    To add insult to injury, the wired ethernet connection I had been running from my TC to the MM Server is now reporting a cable unplugged (it's not), even when I plug it directly into the gateway, though I am able to connect wirelessly.
    Does anyone have any idea what's going on? Why can't I get these ports open? (By the way, I called my ISP and they said they aren't blocking any of the ones I'd want to use for VPN.)
    What is the *better* set up - using the TC as a second LAN, serving its own DHCP addresses, or using it in Bridge mode?
    Why did these changes sever my wired connection?
    I was getting even more problems (like loss of internet connectivity on all devices) using the TC in bridge mode, so I decided to go back to the dual network setup.

    Hello Eric,
    As I mentioned above.
    For external Internet access, I would create a Generation
    1 VM
    and use 2 Legacy Network Adapters for
    the Interfaces . Connect it to the External and Internal network, and then install VM Linux IPFire (How
    to install) and
    configure IPFire with RED and GREEN interface.
    You don't need router or any firewall.
    I have the same set-up that you are trying to do in your lab and it's working great.
    All my VMs / computers on the LAN have their gateway the Linux VM.
    Hope this help.
    Regards,
    Charbel Nemnom
    MCSA, MCSE, MCS, MCITP
    Blog: www.charbelnemnom.com
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

  • How to configure sync with my local ftp server?

    I have used XMarks since now because it hallow me to synchronize my bookmarks with my local server. Now XMarks don't work anymore because it's not more possible to synchronize the passwords.
    Any other alternative imposes to use an external server and I don't want to use an external server. My data must remain on my machine it's absolutely excluded that i use an external unknown server for this.
    The only solution must be a free solution (a real free solution) and the firefox synchronization seems to me the best/only one.
    But I've not found how to configure it to use my own server.
    So how to do it, where are the options to the synchronizer to give my own ftp server or whatever other server it needs?

    iAS 6.0 sp4 officially does only support iPlanet Directory Server 5.0 sp1 and 4.13.
    For more details visit: http://docs.iplanet.com/docs/manuals/ias/60/sp4/ig/prep.htm#42084
    I guess, you can specify the directory server during the time of installation.
    Thanks,
    Rakesh.

  • How to establish connection with the outgoing email server?

    Cannot set up Lightroom 5 email capability with Google Mail. Have confirmed proper smpt address, email and password and error message still comes up:
    "eFailed to establish connection with the outgoing email server. Please make sure you have entered the email account and password correctly."
    How can I clear this up. Help, Adobe!

    Have you checked your Gmail in-box? See if this helps:
    https://forums.adobe.com/thread/1642613

  • How to connect Crystal Report 2008 server with SAP BI/BW server

    Hi ,
    I have downloaded the 60 Days trial version of  "Crystal Report 2008 Server' from sap site to my machine. Now i would like to connect this Crystal server with SAP BI and want to use the data of BI Bex queries and Infoproviders.
    Can you please guide me how to connect them?
    Aslo how can i get the free trial version of Intergration kit ..here please provide me the entire full path of site(to download the Integration Kit).....
    Any inputs would be appreciated!!
    Regards,
    Naween

    Hi Michelle,
    Older versions of CR would allow you to run CR from a network share point but you still had to have a license for each user. Current versions of CR do not allow you to do this any more, possibly using a Citrix or Terminal Server would allow this but you still need a license for each user. Older versions had a Network install option.
    And as suggested exporting to PDF or some other format is fine for end users viewing your output. They are not using CR but Adobe Reader or Word etc. to view the reports, they just can't use the Designer to view the reports.
    Hope this is clear now?
    Thank you
    Don

  • How to setup ftp with dreamweaver and windows server 2003

    Does anyone know if there is a tutorial/article on settinp up Dreamweaver cs3 to use Windows server 2003 as an FTP server...
    any assistance would be greatly appreciated...

    I was able to figure out how to setup the ftp connection, connect to my home server, however,whenever i tried to upload the contents of my website to my server, nothing gets uploaded to the site. I tried putting one page at a time, nothing. tried everything, and still no joy. I can see everything on my local server which is a XAMP package, but nothing on my remote server. Do i maybe need to maybe have a WAMP or XAMP on the Windows Server 2003 or that should not matter. This is new to me so i am learning as i go along.
    Another thing, i was able to create a subfolder in my c:\www.ftproot folder, i can see that folder on my local machine, i'm just not seeing the files in that folder when i do my 'put' with my files.

  • Integrating Sun Java Directory Server with Sun Java Application Server 7

    Hi,
    My basic goal is to implement Single Sign On within the network i,e if the user is inside the company's network and tries to access any application, then he should not be required for Username/password again becuase he is in the network.
    My question is Is this possible with Sun Java System DIrectory server. If yes how can we integrate Directory Server with Sun Java System Application Server 7 2004Q2.
    Please help.
    Thanks

    Directory Server in itself doesn't provide any kind of SSO functions. Basically it is a high performing data repository accessible via LDAP and DSML. It is, however, a key component used by SSO applications like Access Manager. If your applications are web applications then take a look at Access Manager for your SSO needs.
    Regards,
    Scott

  • Replace Snow Leopard Server OS on Mini Server with Snow Leopard non-Server?

    I have a Mid-2010 Mini Server which came preinstalled with Snow Leopard Server. I'm wondering if anyone has had experience with attempting to replace the OS-X Server software with OS-X non-Server in order to run Parallels for the Desktop. If this worked, then one should be able to re-install the OS-X Server software as a client using Parallels. Parallels states that it supports OS-X Server as a client, but the real question is whether one can install the OS-X (non-server) on a Mini which came with the OS-X Server software installed.

    Hi
    Your problem is going to be finding a Client OS that will actually boot and install on the MacMini:
    http://support.apple.com/kb/HT2186
    http://support.apple.com/kb/HT1159
    According to MacTracker the build version of OSX Server 10.6.3 shipping with the MacMini Servers is 10D2235. It may work if you have a comparable client that's fully updated to 10.6.4. One way of finding out is to target disk mode an appropriately updated mac to the MacMini Server. If you can, select the System on that unit as the Startup Disk and see if it boots and works successfully with no kernel panics.
    Tony

  • Can MacMini Server with OS X Lion Server act as an iTunes server for Apple TV2

    Can Mac Mini Server with OS X Server act as an iTunes sever for Apple TV2?

    TomDenver wrote:
    Can Mac Mini Server with OS X Server act as an iTunes sever for Apple TV2?
    If you plan to set up a Mini as media server ...
    Why not directly using the Mini as media center?
    Then you wont need no Apple TV ...
    Then your Mini IS the Apple TV, iTunes sever and so on, especially if e.g. a Elgato or WDTV stick or box is added.

  • Having issues configuring DHCP and with Redundant router

    Hello everyone
    I am new to Cisco and I am having few problems in configuring my topology in Packet tracer.
    I am having redundancy in router and swithes both,
    I have assigned one layer2 2960 switch as a VTP server and asssigned VLANs from that switch then assigned ports to the hosts in access layer switches.
    Problem 1:  If I take my Router1 off I am unable to ping so the pupose of having redundant router does not serve the pupose.
    Problem 2 : I need to assign DHCP server for the users who will be connecting wirelessly with Access Points, so can I configure DHCP on Access Points which I am unable to do so in Packet tracer any idea how? / Or shall I configure the DHCP on Router1 and Router2 and exclude the addresses I have assigned to all the hosts connected using ethernet.
    Also how can I configure Email server in this tolpolgy and where?
    Thank you
    A.K

    Hi Asif, Jeff is right.
    (1) You need to configure either HSRP (Hot standby routing protocol) or VRRP (Wirtual routing redundancy protocol), or GLBP (Gateway load balancing protocol).
    With either of this config, you will be able to configure 1 logical IP address, which will act as a gateway on your computers. However, both routers will need different IP's (all within the same subnet). You will also need to create multiple HSRP groups to support all your VLAN's. So one HSRP group per VLAN. The logical IP in the HSRP group will act as the default gateway on computers within the VLAN.
    Though I don't think packet tracer supports any of the above configs - FYI it's part of the CCNP Switch sylabus. So the above explaination will make sense after you've got a good understanding of HSRP, VRRP and/or GLBP.
    (2) I would recommend setting both the Router as a DHCP server, and configure the Access Point (AP) with a static IP (disable NAT and DHCP on the AP)
    (3) In packet tracer, choose the Server icon and check it's properties. You should find an option to enable EMAIL server. Connect it to any of the Distribution layer switches.
    Hope this helps get you started on the learning curve :-)

  • DB2 and AIX on p570 server with Virtual I/O Server

    Hi, All
    We are implementing a system landscape on IBM p5 570 servers and currently are planning of 3 LPARs with dual VIO-servers on each box.
    Have anybody expirience for this configuration in production systems ?
    Is there any DB2-specific problems for working with virtual SCSI volumes over VIO-server ?
    Is there any IBM/SAP whitepapers/technote for this ?
    Big thanks and sorry for my bad english

    We recently rolled-out 2 p550's configured with dual VIO servers each for redundancy. So far we have installed SAPs Solution Manager and Portals on top of DB2. At this point we are using internal SCSI disk but intend to use SAN disk in future.
    Performance has been good, although these are not yet Production systems. DB2 doesn't care about the virtual disk, since they appear as normal SCSI disks to the OS. I've seen it recommended NOT to use Virtualized disk in production, but I think this may be a CYA-type recommendation.
    There are a couple of White Papers from the "IBM SAP International Competence Centre" in Waldorf, that discuss SAP on AIX 5.3 and Power5. Sorry I don't have the links anymore.

  • How should we communication with Adobe Anywhere from within a panel?

    We are adding a panel to Premiere to help automate the workflows that use Anywhere.  We have found the API that lets us get the Session, Sequence an Selected Item URLs.  However, when we load these using jQuery's Ajax object, we are are getting a 403 to our OPTIONS request because it seems to default to trying to use CORS because we added the Cookie header.  We are able to do load the URLs on a Mac using the same panel with no problem.  The question is should we be able to make Cross Domain requests from the panel, or will we run into the same issues with as with the browsers?  We have a web application that is also making requests, but we are able to get aroudn the cross domain issues be using a proxy in Apache, but since the panel is hosted inside Premiere, I don't know were we would set that up.  Maybe there is a better way to communicate with the anywhere server, otherwise we may need to create our our CORS compliant service to send calls through.
    Thanks.

    Hi,
    I sent you my email address via private message.
    Just to reiterate... unlike browsers, CORS is supported and enabled by CEP in HTML5 extensions. You should just use normal JS functions, there is nothing CEP specific you need to do.
    In light of that, you may have spotted a bug. Please send me the extension so I can take a look.
    Best regards,
    Hallgrimur

  • Add Client access server with DR MBX to server clients from DR site.

    Hello,
    We have a medium size implementation at our company. It is as below,
    - Two mail box servers (MBX1, MBX2) at production Site.
    - One mail box server (MBXDR01 at DR site (Active))
    - One DAG (name: IDKUDAG ) (MBX1,MBX2 and MBXDR01 are members)
    - Two Client access servers at production site (with MBX1 and MBX2)
    There is a high speed WAN connection between two sites.
    What I need to do, I want to add additional CAS server at DR site as in case of production site maintenance or outage I want to migrate the DBs to DR MBX and the CAS server handle mail
    client’s access.
    Can I add a new server at the DR site with the same configuration as the production site???
    Or there is another solution for this case.
    Please advise.
    Best regards,
    Ahmed Salah
    BR Ahmed Aboutabl

    Hi Ahmed,
    The CAS configuration for Exchange service in the second datacenter can be the same configuration as you mentioned. For example, the same internal&external namespaces for OWA, Autodiscover, EWS, OAB etc. in two datacenters.
    Also make sure the certificate has included all needed namespace for the second site. For your reference, here is an article talked about the details of site resilients:
    https://technet.microsoft.com/en-us/library/dd638129(v=exchg.150).aspx
    http://www.msexchange.org/articles-tutorials/exchange-server-2010/high-availability-recovery/designing-site-resilient-exchange-2010-solution-part1.html
    Note: Microsoft is providing this information as a convenience to you. The sites are not controlled by Microsoft. Microsoft cannot make any representations regarding the quality, safety, or suitability of any software or information found there. Please make
    sure that you completely understand the risk before retrieving any suggestions from the above link.
    Regards,
    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact [email protected]
    Winnie Liang
    TechNet Community Support

  • Mac Mini Server with Lion (without Lion Server) ?

    I intend to buy a new Mac Mini and obviously the Server Hardware version is the best option with a i7 Quad Core and 2x HDDs (the option to 2x 750 is $100 whereas the option for 1x750 is $150 !!! for the standard Mac Mini) ... well lets make it shor, I would like the Mac Mini Server hardware but I don't want the Server components in the OS, I don't need them, I don't want to configure them. Does anybody know for sure if I can deinstall the Server components easily ?
    Thx

    Hi RajPad,
    i have not yet found a commandline tool to remove pages. If you're familiar with SQL you can use a tool to connect to the postgresql database where the pages are stored.
    I won't try to write a "howto connect to pgsql on lion" here because i know this has been answered already.
    If youre connected to the database collabd and you have a page url like:
    http://my.lion.server/wiki/pages/P9c196z/somepage.html
    Then your SQL to find the entity is:
    SELECT * FROM entity where tiny_id='P9c196z';
    Note the uid from that result and find and remove all related entries in other tables there after removing this entity.
    I have not excercised that myself because i don't have a system to screw
    Make a Database dump prior to your actions and hope nobody is editing pages while you're at work.
    If you have a plain SQL dump you could pick individual datasets from there to rebuild if something goes wrong. You'll only have to note what you changed to be able to revert.
    Just an idea ....
    Make a copy of your page and compare both pages in database. If one is working and the other aint you should be able to find the difference.
    Good Luck
    Andreas

Maybe you are looking for

  • RFC hangs with a call to function module SSFC_PARSE_CERTIFICATE

    Hello , We are working on BI 7.0  SP9 . When we try to test the RFC connection from the WAS Abap to the portal ( WAS JAVA ) using  SM59  , the test is hanging but we can read in the bottom of the screen 'Connexion bcv51sf2... OK' !!! The test connect

  • How to call multiple request to CRM and R/3 without BPM

    Hi all I have a scenario where a SOAP request will come to XI via webservice I then have to call an interface mapping which has Java mapping in it(the java code is basically calling an RFC in CRM) - then i'll receive the response of interface mapping

  • Why does LR3 not produce sRGB compatible images?

    An image that I fine-tuned in the Develop module will look flatter  (less-saturated) when exported as a JPG and viewed in a browser, if the  browser is not colour-managed. This happens despite the fact that the image is exported using the sRGB colour

  • Undoing changes in ApplicationModule

    Hello, I want to set restore points for the changes in ApplicationModules. E.g. I've got a main screen and second dialog that runs in the same binding context as the main screen. Before I open the second dialog I want to set a restore point so that I

  • OBIEE Fragmentation using Essbase as data sources

    Hi- How can we create a fragmentation on OBIEE taking data sources from 2 cubes? For example: I have 3 dimensions (same outline on both cubes): Account: - Account 1 - Account 2 Product: - Product 1 - Product 2 Year: - Y2008 - Y2009 And how can we set