Forums

Mark T
Mark T
Offline
Resolved
0 votes
Hello --
I have a question about Gateway Mode. I have two NIC's installed and testing in a lab environment. I have the Community edition and it's set to Gateway Mode. I have one NIC#1 set to External (for my internet connection 192.168.1.50), and NIC#2 set to LAN for internal desktops, etc. (192.168.1.51) What I'm seeing is that the ports for SSH (22) and management (85) are only open on NIC#1 (External) --I have firewall rules enabled; therefore, that's what they're accessible via the External connection. Where I'm confused is than on the LAN side, NIC#2 (192.168.1.51), no ports at all are open --neither the management (85) or ssh (22). Any idea why the LAN side ports are blocked by default, I would have though once set to LAN that NIC would be wide-open. Any suggestions why this is happening?

Couple attachments below of setup and scans of external and internal.

Thanks!
Saturday, June 24 2017, 10:18 PM
Share this post:
Responses (2)
  • Accepted Answer

    Sunday, June 25 2017, 08:00 AM - #Permalink
    Resolved
    0 votes
    It is happening because you have both NIC's on the same LAN subnet. Routing will not work in this case. What is most likely happening is that ClearOS is receiving your nmap on its .50 interface, but, because of the routing issues, replying on the .51 interface which nmap will not be listening on. If you are testing ClearOS on your LAN like that, with the ClearOS WAN connected to your LAN, really you will need a separate network/machine to connect to the ClearOS LAN. Is should always be on a different subnet from you "WAN".

    FWIW, it is best to avoid the 192.168.0.0/24 and 192.168.1.0/24 subnets on you LAN.
    The reply is currently minimized Show
  • Accepted Answer

    Mark T
    Mark T
    Offline
    Sunday, June 25 2017, 11:13 AM - #Permalink
    Resolved
    0 votes
    Thanks for the reply, that's exactly what it was. I moved the LAN NIC onto a separate VLAN, gave it a 10.x.x.x subnet and now it's working just as you'd expect it to --the ports are now open on the LAN side.

    I appreciate the help!

    Thanks.
    The reply is currently minimized Show
Your Reply