Ask Experts Questions for FREE Help !
Ask
    botham7's Avatar
    botham7 Posts: 2, Reputation: 1
    New Member
     
    #1

    Aug 26, 2008, 02:34 AM
    IPCOP Problems
    I have set up IPCOP threw a Windows Xp machine. The red interface is connected to a router with multiple WAN ports(2) that is connected to two ADSL modems. Now the problem is I can access the internet but my e-mail and secure websites(https) like banks does not work. I have set a policy up on the router with the two WAN ports to use only the one WAN for those problem sites and also I have configured port forwarding on IPCOP. It does not work, if I cut IPCOP out then everything works. Any advise please-Thank You -Martin.
    chuckhole's Avatar
    chuckhole Posts: 850, Reputation: 45
    Senior Member
     
    #2

    Aug 27, 2008, 09:48 AM
    Did you also configure the "problem" WAN port to route back to the other WAN port. If you are forwarding your port 443 protocol on to the other connection, it must have a return pathway.
    botham7's Avatar
    botham7 Posts: 2, Reputation: 1
    New Member
     
    #3

    Aug 27, 2008, 09:19 PM
    How do you do that? And thank you for answering.
    chuckhole's Avatar
    chuckhole Posts: 850, Reputation: 45
    Senior Member
     
    #4

    Aug 29, 2008, 03:30 PM
    The more I read your post, the more I realize that your setup is not what I envisioned. It sounds like you are simply connecting one LAN connection in a "Y" to two WAN ports, each with its own Internet connection. Then you want to separate the HTTPS traffic from the rest of the traffic.

    The very nature of HTTPS and HTTP is such that they will often work together within the same web pages. There is often mixed content within the same web page. This is not always so but it is quite common. HTTPS sessions are often initiated with HTTP and then redirected to another server or different folder structure in which the security certificate is required. Also, the retrieval of the security certificate is performed via HTTP and once installed on the client, the HTTPS protocol is then initiated.

    Another way that mixed content is performed is via secondary connections. This is common with sites like MyYahoo where you sign in for your own custom start page. The connection to the site is initiated with HTTP and then starts your content download via a random highport designation. This means that they will assign your connection with a TCP port starting at 1024 and up. And often the content updates are serialized so that they increment your port by one each time you receive an update. For example, they may start your connection at port 80, your cookie logs you in and then they assign your connection to port 1354. Then after your next update of your stock ticker or news content, you are then incremented to 1355 and so on. This way, they can track who you are and what content you have asked for. If you block all highports (anything over 1023), you would effectively disable this type of streaming content. And if you try to push the content over to a different WAN connection mid-stream, the return pathway has been blocked off.

    What it boils down to is that it would be almost impossible to separate the two (HTTP and HTTPS) across two WAN connections. Your greatest security is not in what you allow but in what you disallow.

    What you are trying to do would be much easier achieved with protocols that work independent of each other. For example, forwarding your SMTP requests to a different WAN connection and blocking all incoming traffic on that connection except SMTP.

    If you are attempting to load balance and perform a failover of your Internet connections, this can not be achieved with the hardware that you have on hand. Your IPCOP device is designed for content filtering and security and not multi-path load balancing. If you are using the two Internet connections for VPN, SMTP, Internet, etc. then you can manually balance your loading by forcing client VPN and WAN VPN over one connection and Internet access and SMTP over the other. Then you can secure each connection type based on its purpose.

Not your question? Ask your question View similar questions

 

Question Tools Search this Question
Search this Question:

Advanced Search

Add your answer here.


Check out some similar questions!

Ipcop [ 3 Answers ]

Hi. I have just installed Ipcop on a second machine, as a firewall between me and the internet. But I can't go any further. :mad: I am VERY!! Frustrated. I know NOTHING about Linux. I can access the IPCOP computer, but I can't get to the internet, I don't even know if IPCOP is getting to the...

How to view WEB Cam when IPCOP firewall is there [ 1 Answers ]

Dear Sir, I have IPCOP firewall, due to strong fillitering of IP Cop I am not able to view any WEB CAM of our other network, It is always showing the following message "Your behind Firewall". Kindly solve my this problem Regards Raj


View more questions Search