I am trying to setup to secure a redirect public port to a private port

I i am trying to setup to secure a redirect public port to a private port to a Microsoft server exchange
A user coming from the outside(Untrusted security level 0) will connect to IIS server in the DMZ(Trusted security level 50) with a port 443 to a PIX 515 , the IIS server has a application called Detour Service(Service transparently reroutes any TCP connection from one IP Port to any other IP Port) will initiate a connection to Microsoft server exchange to the inside(trusted security level 100).
Do you think it is the right solution I term of security?yes or no, are do you have a better solutution
Thanks
User port destination 443(outside)>>>>>> IIS server port destination 9999(DMZ)>>>>>>>>>>> Microsoft server exchange(inside)

Actually the connection from lower security level to higher security level is blocked. You can apply an access list to limit traffic from inside to outside, or allow traffic from outside to inside. For transparent firewall mode, you can also apply an EtherType access list to allow non-IP traffic.

Similar Messages

  • Proper setup for a network with Public Static IPs and Private IPs

    hello all-
    i am trying to setup a network with public static IP addresses and local (internal) IP addresses with 192.168.xxx.xxx format. i will try to explain as best i can how i have it set up and what my issues are.
    i have COX business services in my home and 8 static public IPs assigned to me. i have tried setting this up and everything internally (192.168.xxx.xxx) works fine and all the devices can get to the outside world fine but when i try to access ANY of the devices on the public IPs from outside the network i get absolutely nothing. the browser just times out and i cannot ping the devices even though COX can see and says the devices are bridging over. COX is unable to get a response when they ping the devices either.
    one of the devices is a Synology NAS with one Ethernet port that is using a public IP and the other using a 192.168.xxx.xxx address. when the Ethernet port is setup using a static public IP COX can see it but they get no response from a ping and when they go to the address to get the login page the browser times out. when i reconfigure the port for DHCP it grabs a public DHCP address and when COX pings that they get a response AND they are able to type the DHCP adress in their browser and get to the login page no problem. when i switch back to the static IP they can see it but again are unable to get a response from a ping and are unable to go to the login page.
    my setup is:
    COX Modem (only has 1 Ethernet port) ====>> 8 port NETGEAR Gigabit switch (all devices with Public IPs are plugged into the NETGEAR switch)
    NETGEAR switch ====>> WAN Port on Airport Extreme (latest version w/all software updates)
    LAN Port Airport Extreme ====>> CISCO 2960 48 port Gigabit Switch (all internal devices are plugged into the CISCO switch)
    like i said everything with the 192.168.xxx.xxx connects and i can connect to just fine but none of the devices with public static IPs can be pinged even though COX can see them bridging over. i have tried all new cables on the devices and that didn't work so it has to be something with my setup.
    do i need to add another router to this configuration because i have extra airport extremes lying around i can use if someone could just tell me how the setup should be. i also have a few ports open on the CISCO switch; is there a way i can use it for the 4-5 devices that have public IPs? or will that cause a problem with all the other devices plugged into it with the 192.168.xxx.xxx IP addresses?
    i'm not a networking guru (obviously) so if you are able to help me get this setup properly can you try not to use Doctoral Level syntax in your response? i would greatly appreciate it!
    i appreciate any and all help... thx in advance!

    Duplicate posts. 
    Go HERE.

  • I am trying to receive my security questions but iTunes keeps sending it to the wrong email, I have the email setup on Apple ID.

    I am trying to receive my security question but iTunes keeps sending it to the wrong email, I have the right email on the settings and Apple ID

    I did it before ios7 and it wasn't a problem but now it is:/

  • HT5570 Can any one let me know how to setup new security question answers required for purchases of which the previous answers been forgotten.

    I am trying to do some purchases from my account balance of USD 50.00. But not able to do it as I have forgot the answers for security questions. Thus, I have been trying to setup new answers for that, but could not find any way to do so. Please help me on this.

    You need to ask Apple to reset your security questions. To do this, click here and pick a method; if that page doesn't list one for your country or you're unable to call, fill out and submit this form.
    (118301)

  • Help. Just got the latest and greatest ipod touch.  When trying to setup icloud, my email address is verified but when I touch settings, icloud, account tries unsuccessfully to verify account.

    Help. Just got the latest and greatest ipod touch.  When trying to setup icloud, my email address is verified but when I touch settings, icloud, account tries unsuccessfully to verify account.

    Why am I sometimes asked to verify my Apple ID by email?
    When you create a new Apple ID or make certain changes to your account, Apple will require you to sign in by following the link in a verification email. This is to help protect your identity and keep your account secure. Some Apple services, such as FaceTime and GameCenter, require email validation.
    How do I verify my Apple ID by email?
    Simply follow the link in the verification email that says "Verify Now." Sign in with your current Apple ID and password, then click Verify Address. You can also verify by signing in at My Apple ID. You'll receive an email prompting you to verify.

  • How do I setup a secure wireless AirPort network that allows internet shari

    Hi everyone,
    I'm trying to setup internet sharing over a wireless Airport network between my flatmate's iMac and my G4 Powerbook. We both have Norton Confidential installed, which includes a Firewall feature, which may be making this more difficult.
    I thought I understood the basics of setting up secure Airport network, and the basics of Internet sharing. But with all the variations I've tried, I've only ever managed to create a secure network that won't share internet, or a network that shares internet but doesn't seem to be password protected. I never seem to get all three, and I can't figure out why.
    From startup/login on both machines, what are the steps I need to follow?
    Many thanks,
    Andrew

    You enable wireless security on the base station, by using the AirPort Utility. You basically have four choices: None, WEP, WPA, or WPA2. (Note: These are in order of least to most security.)
    Here are the basic steps:
    AirPort Extreme Base Station Setup (AEBSn) - Wireless Encryption
    Setup the AEBSn
    Either connect to the AEBSn's wireless network or temporarily connect your computer directly (using an Ethernet cable) to one of the LAN ports of the AEBSn, and then, using the AirPort Utility in Manual Mode, check these settings:
    AirPort - Wireless
    o Wireless Security: <None | WEP (Transitional Security Network) | <b>WPA/WPA2 Personal | WPA2 Personal>
    o Wireless Password: <enter your desired password>
    o Verify Password: <reenter your desired password>

  • Trying to setup iCloud email in outlook followed directions got error on smtp instructed to contact isp

    Trying to setup iCloud email on pc with outlook followed manual instructions as directed
    Outlook accepted all input but failed when sending test message in outlook
    Message state error smtp contact ISP

    This what I set our 2003 at least a dozen times, nothing what so ever changes, unless I use these entries we can not get a TEST of the account to run through to the end.
    However with that we now always get the error 0x800ccc7d every day now for the first few emails.
    Incoming mail server (POP3): pop.verizon.net
    IncomingServerPort Numbers: 995
    Outgoing mail server (SMTP): smtp.verizon.net
    Outgoing ServerPort Numbers: 465  Your Verizon Online user name
    Your Verizon Online password
    Make sure "This server requires a secure connection (SSL)" is checked.

  • Trying to setup e-mail account

    I have been trying to setup my telus e-mail account and message keeps popping up:
    Authentication method are not supported by server.
    Any idea how to setup?

    Are you usig a different ISP than the other stup that worked? If so it's likely Port related.
    I have fiddled around with different settings in the account like turning on SSL...
    They don't mention that, but...
    see J D McIninch's post here...
    http://discussions.apple.com/thread.jspa?messageID=9135895&tstart=0
    For Verizon, use the following settings:
    server name: outgoing.verizon.net
    ports: use default ports (25, 465, 587)
    authentication: password
    username: [email protected]
    password: yourVerizonPassword
    For the record, Verizon does support connections from e-mail clients. They generally don't know Apple Mail, and they don't support secure sockets layer.

  • Trying to setup PHP site (friendica) with nginx on localhost

    Hi, just new here :-)
    Started to use Arch a couple of month ago and sofar everything went fine thanks to the great documentation!
    Now I tried to setup friendica on my computer for testing some modifications but I just fail on installing the required modules :-(
    I already installed:
    php
    php-fpm
    php-gd
    php-cgi
    php-mcrypt
    mariadb
    nginx
    phpmyadmin
    But I still get the following errors:
    GD graphics PHP module (required)
    Error: GD graphics PHP module with JPEG support required but not installed.
    OpenSSL PHP module (required)
    Error: openssl PHP module required but not installed.
    mysqli PHP module (required)
    Error: mysqli PHP module required but not installed.
    Generate encryption keys (required)
    Error: the "openssl_pkey_new" function on this system is not able to generate encryption keys
    If running under Windows, please see "http://www.php.net/manual/en/openssl.installation.php".
    Command line PHP
    Could not find a command line version of PHP in the web server PATH.
    If you don't have a command line version of PHP installed on server, you will not be able to run background polling via cron. See 'Activating scheduled tasks'
    PHP executable path Enter full path to php executable. You can leave this blank to continue the installation.
    Url rewrite is working (required)
    Url rewrite in .htaccess is not working. Check your server configuration.
    My nginx.conf looks like this:
    #user http;
    worker_processes 1;
    error_log logs/error.log;
    #error_log logs/error.log notice;
    #error_log logs/error.log info;
    #pid logs/nginx.pid;
    events {
    worker_connections 1024;
    http {
    include mime.types;
    default_type application/octet-stream;
    #log_format main '$remote_addr - $remote_user [$time_local] "$request" '
    # '$status $body_bytes_sent "$http_referer" '
    # '"$http_user_agent" "$http_x_forwarded_for"';
    #access_log logs/access.log main;
    sendfile on;
    keepalive_timeout 15;
    gzip on;
    gzip_comp_level 1;
    server {
    listen 80;
    server_name localhost;
    location ~ \.php {
    root /srv/http/project;
    fastcgi_pass unix:/var/run/php-fpm/php-fpm.sock;
    fastcgi_index index.php;
    fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
    include fastcgi_params;
    location / {
    root /srv/http/project;
    index index.php;
    Can someone help me?

    Thanks for the quick answer!
    progandy wrote:Did you enable all necessary modules in your php.ini?
    I had a look at /etc/php/php.ini but I can't find things (with my knwoledge) that seem to be important....
    progandy wrote:Then you'll have to create the rules in the .htaccess in the format nginx understands.
    Haven't checked that yet...
    progandy wrote:https://github.com/friendica/friendica/ … tall-Guide
    This is quite complicated. Seems like I'd need to study  to understand it:-(
    progandy wrote:http://jcsesecuneta.com/tome/labox/sett … -on-nginx/
    This one seemed clear I changed my nginx.xonf according to it:
    server {
    listen 80;
    server_name localhost;
    root /srv/http/project;
    access_log off; # If you are using 'Analytics' type software for tracking, keep this 'off'
    log_not_found on; # Turn on if you want to track "not found" errors
    error_log /srv/http/project/logs/error.log info; # valid values: debug, info, notice, warn, error, crit
    #rewrite_log on; # Uncomment if you want to debug your rewrites (then change 'crit' above to 'notice')
    # block stuff early
    # Do not log favicon.ico and robots.txt stuff
    location ~* /(favicon\.ico|robots\.txt) {
    allow all;
    access_log off;
    log_not_found off;
    # Return error 444 for these files
    location ~* ^.+\.(bzr|git|log)$ {
    access_log off;
    log_not_found off;
    return 444;
    # Deny public access to ~ (bak) files
    location ~* ~$ {
    access_log off;
    log_not_found off;
    return 444;
    # Friendica #
    location / {
    try_files $uri $uri/ @friendicacleanurl;
    location @friendicacleanurl {
    rewrite ^/(.*) /index.php?q=$uri last;
    break;
    # Security: Friendica #
    # block public access to .htaccess and .htconfig.php
    location ~* /\.ht {
    access_log off;
    log_not_found off;
    return 444;
    # block public access to .tpl files located in /view/ folder
    location ~* /view/(.*)\.tpl$ {
    access_log off;
    log_not_found off;
    return 444;
    # block public access to /util/ folder
    location ^~ /util/ {
    access_log off;
    log_not_found off;
    return 444;
    # Deliver static files directly #
    # images (Friendica)
    location ~* /(addon|images|library|spec|util|view)/(.*)\.(bmp|cur|gif|ico|j2k|jp2|jpe|jpeg|jpf|jpg|jpm|jpx|mj2|mng|png|svg|svgz|thm|tif|tiff|webp)$ {
    add_header Pragma "public";
    add_header Cache-Control "public";
    access_log off;
    log_not_found off;
    expires 28d;
    # redirect 50x error pages #
    error_page 500 502 503 504 /50x.html;
    location = /50x.html {
    root /usr/share/nginx/html;
    internal;
    # enable PHP #
    location ~ \.php$ {
    try_files $uri =404;
    fastcgi_split_path_info ^(.+\.php)(.*)$;
    fastcgi_pass 127.0.0.1:9000; # Comment if you want to use sock instead of tcp
    #fastcgi_pass unix:/var/run/php-fpm.sock; # Uncomment to use sock instead of tcp
    fastcgi_index index.php;
    fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
    include /etc/nginx/fastcgi_params;
    but then nothing works anymore! When I try to restart nginx I get:
    sudo systemctl status nginx.service
    nginx.service - A high performance web server and a reverse proxy server
    Loaded: loaded (/usr/lib/systemd/system/nginx.service; enabled)
    Active: active (running) (Result: exit-code) since Sa 2013-12-28 18:05:13 CET; 1 day 22h ago
    Process: 15591 ExecReload=/usr/bin/nginx -g pid /run/nginx.pid; daemon on; master_process on; -s reload (code=exited, status=1/FAILURE)
    Process: 318 ExecStart=/usr/bin/nginx -g pid /run/nginx.pid; daemon on; master_process on; (code=exited, status=0/SUCCESS)
    Process: 314 ExecStartPre=/usr/bin/nginx -t -q -g pid /run/nginx.pid; daemon on; master_process on; (code=exited, status=0/SUCCESS)
    Main PID: 320 (nginx)
    CGroup: /system.slice/nginx.service
    ├─ 320 nginx: master process /usr/bin/nginx -g pid /run/nginx.pid; daemon on; master_process on;
    └─10295 nginx: worker process
    Dez 30 14:59:10 thinker nginx[10294]: 2013/12/30 14:59:10 [notice] 10294#0: signal process started
    Dez 30 14:59:10 thinker systemd[1]: Reloaded A high performance web server and a reverse proxy server.
    Dez 30 16:12:58 thinker systemd[1]: Reloading A high performance web server and a reverse proxy server.
    Dez 30 16:12:58 thinker nginx[15396]: 2013/12/30 16:12:58 [emerg] 15396#0: "server" directive is not allowed here in /etc/nginx/nginx.conf:1
    Dez 30 16:12:58 thinker systemd[1]: nginx.service: control process exited, code=exited status=1
    Dez 30 16:12:58 thinker systemd[1]: Reload failed for A high performance web server and a reverse proxy server.
    Dez 30 16:15:33 thinker systemd[1]: Reloading A high performance web server and a reverse proxy server.
    Dez 30 16:15:33 thinker nginx[15591]: 2013/12/30 16:15:33 [emerg] 15591#0: no "events" section in configuration
    Dez 30 16:15:33 thinker systemd[1]: nginx.service: control process exited, code=exited status=1
    Dez 30 16:15:33 thinker systemd[1]: Reload failed for A high performance web server and a reverse proxy server.
    What's wrong?

  • Trying to setup mail account

    I am trying to setup my email account in the mail program. I have my mobile me email working in there properly, but my charter email is not getting setup correctly. Everytime I go to set it up, I get a message stating that "Mail cannot send my password securely to the server", and asks to continue or setup manually. I've tried both ways several times, and it never works. I've even contacted my ISP, and they walked me through the whole setup, and say its a problem with my computer settings. I know my password is correct, and have even reset it to be sure. I can get into my email account just fine on the online webpage and on my iPhone.
    I'm guessing there is a security setting somewhere i'm not aware of.... Please help..

    Take a look at this link, http://support.apple.com/kb/TS3276

  • I am trying to setup VPN with QuickVPN

    Hi I am trying to setup VPN with WRVS4400N and Quick VPN on client side. I am fairly new to VPN and did some research and looked through the manual but can't seem to get it to work so far and from what I noticed many people are having this problem. So hopefully someone can tell what the problem is or at least point to right direction on solving this.
    Basically it gives the "Failed to establish connection" generic error, shows it almost instantly..
    It also showed the certificate error before but then I read about putting it in the installation directory and it stopped showing it, and whats strange is later I removed it but it doesnt show the error any longer, so don't know if its caching it somewhere or what can be going on...
    In effort to look for answer and test things out I tried to connect to another location and setup a WRV200 router, I also get the same error but not instantly, it even shows "Activating Policy" but then doesn't go farther and shows the generic error...
    Also with this setup strangly it always shows the certificate error, no matter if I put one in directory or not... Even tried to name it as the WRVS4400N certificate name...
    Anyway VPN IPSec is disabled, and Client Accounts are configured and changed password several times to make sure its correct, VPN Passthrough enabled on all 3 options.
    I tried to disable Windows Router, I also have a router in place do I possibly need to open some type of ports for the QuickVPN client?
    Don't know yet whats going on if I am missing something or if there is some problem that needs work-around but if you know the answer or guesses of answer please let me know.

    Hi Aleksandr,
    since this question is about a product in the Cisco Small Business / Linksys range, I suggest you move it to the community, where you will have a better chance of getting expert advice.
    best regards,
    Herbert
    Cisco Moderator

  • Error when trying to access a secured web service from Forms 10g 10.1.2.3

    Hello,
    I'm trying to access a secured web service from Forms10g 10.1.2.3 but i'm getting the next error when pressing the button the first time:
    java.rmi.RemoteException: ; nested exception is: HTTP transport error: javax.xml.soap.SOAPException:
    java.security.PrivilegedActionException: javax.xml.soap.SOAPException: Bad response: 401 UnauthorizeWhen i press the button a second time i got this error:
    javax.xml.rpc.soap.SOAPFaultException: The SOAP request is invalid. The required node 'Envelope' is missingThis is the code i have in my button:
    DECLARE
    jo ora_java.jobject;
    pdfObject ora_java.jobject;
    pdf     varchar2(900);
    rv varchar2(100);
    ex ora_java.jobject;
    BEGIN
    JO := SEARCHSOAPCLIENT.new;
    SEARCHSOAPCLIENT.setUsername(JO,'weblogic');
    SEARCHSOAPCLIENT.setPassword(JO,'welcome1');
    pdfObject := SEARCHSOAPCLIENT.quicksearch(JO,'1234',NULL);
    pdf := SEARCHSOAPCLIENT.tostring(pdfObject);
    message(pdf);
    message(' ');
    EXCEPTION
    WHEN ORA_JAVA.JAVA_ERROR then
    message('Unable to call out to Java, ' ||ORA_JAVA.LAST_ERROR);
    WHEN ORA_JAVA.EXCEPTION_THROWN then
    ex := ORA_JAVA.LAST_EXCEPTION;
    :error := Exception_.toString(ex);
    END;When i run it from JDeveloper it works, this is a portion of java code the proxy web service has:
    import oracle.webservices.transport.ClientTransport;
    import oracle.webservices.OracleStub;
    import javax.xml.rpc.ServiceFactory;
    import javax.xml.rpc.Stub;
    public class SearchSoapClient {
        private webservicesproxywebcontent.proxy.SearchSoap _port;
        public SearchSoapClient() throws Exception {
            ServiceFactory factory = ServiceFactory.newInstance();
            _port = ((webservicesproxywebcontent.proxy.Search)factory.loadService(webservicesproxywebcontent.proxy.Search.class)).getSearchSoap();
            this.setUsername("weblogic");
            this.setPassword("welcome1");
            System.out.println("callling from _port "+ _port.quickSearch("1234234", null));
         * @param args
        public static void main(String[] args) {
            try {
                webservicesproxywebcontent.proxy.SearchSoapClient myPort = new webservicesproxywebcontent.proxy.SearchSoapClient();
                System.out.println("calling " + myPort.getEndpoint());
            } catch (Exception ex) {
                ex.printStackTrace();
         * delegate all operations to the underlying implementation class.
        public QuickSearchResult quickSearch(String queryText, IdcPropertyList extraProps) throws java.rmi.RemoteException {
            return _port.quickSearch(queryText, extraProps);
        }Also the secured web service was generated from Webcenter Content 11.1.1.6 that is why it's a secured web service.
    Kind Regards
    Carlos

    Without going into any technical discussion about the code, my first question is what JDK version was used to create this which was imported into the form? Understand that Forms 10 runs on JDK 1.4.2, so if you used any newer JDK version, likely there will be problems.

  • Issues when trying to setup alternate sync location of OneDrive for Business / SharePoint 2013 Libraries

    Hello,
    I have an issue that prevents me from choosing the alternate location of sync'ed OneDrive for Business folders. I'm trying to setup an alternate location for synchronization, using the guidelines found in the Office support web site.
    The option to replace the default sync location appears the first time a SharePoint 2013 Library or OneDrive for Business is setup for synchronization.
    Here would be a link to a snapshot (since my account has not been verified): /Forums/getfile/443247
    At this point, the Library or personal OneDrive folder syncs correctly and the files are stored in the alternate choosen location.
    However, on when trying to setup an additionnal Library for synchronization, the alternate sync location has not been saved and reverts to the default sync location. Furthermore, the option to replace the default sync location does no longer appear
    on the dialog box.
    Here would be a link to a snapshot (since my account has not been verified): /Forums/getfile/443249
    I have tried by first sync'ing a SharePoint 2013 Library (instead of the personal OneDrive for Business folder) with the same result. Meaning that the first SharePoint 2013 Library correctly sync's in the alternate location of my choosing. However,
    any subsequent attempts to sync either a SharePoint 2013 Library or the OneDrive for Business folder results in them being sync'ed to the original default location in a folder under the user's profile directory.
    I'm using Office Professional Plus 2013 (64bits). The version of Groove.exe is 15.0.4605.1000 (12th March 2014 - 13 383 360 bytes).
    Is there something I'm missing ?
    Thanks for any help on this issue.

    Hi SpringComp,
    You can change the root path for libraries you sync to your computer, though you can do this only if you’re not currently syncing any libraries. If you’re already syncing at least one library and you want to change the path, you must first
    stop syncing all libraries. Then, the first time you run the OneDrive for Business wizard to sync a library to your computer, you’ll see an option to change the location.
    More information, please refer to the link:
    http://office.microsoft.com/en-001/support/change-the-location-where-you-sync-sharepoint-libraries-on-your-computer-HA102893480.aspx
    I hope this helps.
    Thanks,
    Wendy
    Wendy Li
    TechNet Community Support

  • I'm trying to reset my security questions because I got a new iPad mini and I don't remember the security questions but when I try to reset it it says email sent, but I never get the email. Help!

    I'm trying to reset my security questions because I don't remember them. But every time it says they have been sent to me. I never receive them and I know for sure I'm on the right email address. Help!

    You can contact iTunes Support and have them reset them:
    ACCOUNT SECURITY CONTACT NUMBERS
    Cheers,
    GB

  • I'm trying to recover my security questions, but my alternate email address on the link does not match the one I have put in my Apple ID, on the link it is has an old one that no longer exists. Has anyone else been through this or knows how to help m

    I've been trying to remember my security questions for ages, and I can't seem to remember them. On my Apple ID I have changed my alternate email address because the previous one was deleted, but when I go on the "Password and Security" page on my Apple ID and there is a link saying "Forgot your answers? Send reset security info email to ************@*******.com" but it is giving me my old email that does not match my current one on my Apple ID and no longer exists. I have been trying for very long to recover my security questions' answers, but Apple is not coping with me.
    Has anyone been through this or knows how to help me?
    Thank you.

    You need to ask Apple to reset your security questions. To do this, click here and pick a method; if that page doesn't list one for your country or you're unable to call, fill out and submit this form.
    (122986)

Maybe you are looking for