What's new

Little Dilema

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

warbird026

New Around Here
Hello Everybody!

This is my first post and I'm excited...I love this site and have for a long time. I hope that I am putting my first post in the correct spot, but if I'm not...mods...feel free to move it!

I am looking for some advice from the pros that are running around here. I have an okay setup at home and I'm looking to make some changes, but I want to get some outside input on different ways of setting it up. I think what I'll do is list what I have, what I want to do, and what is currently going on and hope for the best. Oh, and thank you in advance for any and all advice/suggestions/ideas that you all give...I truly appreciate it!

Have:
HP proliant server running Server 2012 R2 Essentials (not handling DHCP currently). Installed in this server is an Intel 4 port gigabit NIC aside from the onboard NIC and iLO port

HP procurve 24port gigabit switch (1800-24g)

Zyxel USG20W router/firewall (soon to be replaced with a USG50 and NWA5123 access point)

Canon Imageclass printer
4 desktops
3 laptops
2 mobile devices
.............and a partridge in a pear tree................

Currently everything is running great, but to print wirelessly I had to create a bridge from the wlan to the lan. I cannot get the RWA or VPN on the server to work and I'm wondering if it is due to the bridge changing the ip's of everything on lan1 and therefore messing with the default NATs. I know my isp blocks port 80, but they do not block 443. I'm no rookie, but not a pro and I know I'm missing something here. In my little peanut mind I want to reconfigure everything and try and not configure a bridge to print wirelessly from a laptop or mobile device. I'm thinking let the server handle dhcp and dns, connect everything to the switch and only the server to the router/firewall, but then where would that leave me for printing from a laptop? Would that work? If the server is handing out ip's then would the router only pass along an ip via RF to my laptop and therefore be able to print without the stupid bridge?

Did any of that rambling make any sense???

In short, I'm looking for ideas and suggestions; I've already decided to start over with what I currently have I'm just looking for the best or most efficient way of setting up everything I have to be able to accomplish what I want. I use the server for backups, folder redirections, network shares, media streaming (a little) and plan to open up a VPN from here to the in-laws as well as keep remote access from my mobile and laptops when away.

Thank you again for your input!!!
:D
 
How did you "bridge" the WLAN and LAN?

Mor details on the VPN and RWA (what is that?) problem please.
 
How did you "bridge" the WLAN and LAN?

Mor details on the VPN and RWA (what is that?) problem please.

Sure...sorry about that. Apparently, the Zywall USG20W has the wireless running on a different network than than the LAN...this is default. By that definition one working on a laptop wirelessly would not be able to print to a network printer that is setup on the LAN. I went and created and zone and added the wlan and lan1 as members to that zone, assigned IP and sub, created the dhcp pool and pool size and then under routing added this new zone/slash rule. There is a walkthrough on this out on the web...

http://www.zyxel.se/web/support_pro...yGroupNo=367FE6C2-C958-4FDD-BA2D-6404D45BB7EA

I'm fairly new to Zywall equipment...I like it, but the UI and how setting things up are different and a little confusing. I can't help but think there is a better way to address the above scenario without going that route. As far as the RWA and VPN goes, the VPN is not up through the server yet. I haven't made it that far yet due to not being able to get RWA up. RWA, or remote web access, is a role that is installed on the server for accessing applications and data from virtually anywhere that you have an Internet connection and by using almost any device...there is an app that is built into my windows 8 phone that allows me to administer my server from my phone...pretty clever. There are certain settings that must be made in the router for it to work and the primary thing is to open up 443 for https. I "think" I have that done in the router, but I'm also pretty sure that the bridge has become a problem. When I created the bridge it spun a whole new set of ip's that were nowhere close to the originals I had. I know there is a NAT in my modem, then on the front side of my router which will then give me my ip's via dhcp, but those ip's are no longer in play with this "bridge".

I hope that helped clear some things up. Thank you for replying as well!
 
I would not have wireless on a separate subnet. I'd just move it to the same VLAN if you can. Or at least not have a separate IP range.

For remove access and VPN, you'd best try ZyXEL support. Every product is different and especially with products like the Zywall, to get stuff through the firewall, you need to both open the proper ports and create a proper firewall rule.
 
I don’t really have a picture of your network in my mind. How are the 5 NICs connected in the server? What are their networks?
 
Hi,
Really, if OP does not have his network block diagran drawn on a piece of paper, then having it on a piece of paper is lot easier to come up with a plan of attack for the problem or issues or improvement.
 
You've got some very serious hardware my friend for that network of yours. :eek: More power to you!

So that Zywall is a BEAST of a router. It's beyond even small business class, it's entry level enterprise class. And with that comes--a 900+ page manual for the USG50. :eek: It's a lot of reading as I've been studying this series for a 4 site multi-state WAN via VPN.

The good think is that I've heard wonders about their telephone support. You simply tell them what you want to do and they'll log in and do it.

Now, what it seems like has happened is that you have two different lans (possibly vlans) with interlan routing enabled. What you actually want is the wireless to be a part of your primary wan. And yes, I think all of this has messed up your IP addresses and hence your servers.

I'd place a call to Zyxel and talk to their support people to set up the USG correctly. After that, I think everything will work great. :)

Oh, and if you're going to sell that USG20W, I'd be interested. It will give me a great testbed to get used to their UI before I jump in.
 

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top