Anyone use Untangle, I need a little Help :)

rhansen5_99

2[H]4U
Joined
Nov 12, 2001
Messages
2,153
Ok I am a noob of sorts and I have searched a bunch to no avail, so any help would be greatly appreciated. Basically our firewall at work is starting to have serious hardware issues and our throughput is getting smashed. So I would like to setup a untangle box in its place as well as our router.

I have attached a picture to try to explain our current configuration and what I would like to do with our new untangle box.

We currently have a t1 fiber line run to a cisco ME3400 router, which connects to a Cisco 2600 --> Juniper Netscreen 25 --> internal network.

I want to replace both the cisco 2600 and the netscreen in this process, to streamline our amount of equipment and the configuration necissary.

I cannot touch the Cisco ME3400 because that is att's. But this spits out our 12.80.x.62 ip address, where it grabs a 12.80.x.61 from th isp.

So I have tried to setup the External adapter with the ip:12.80.x.62, with the gateway 12.80.x.62 and the dns 4.2.2.1 and 4.2.2.2

I would like the untangle box to resolve in our network as 10.0.0.1

On the internal port I would like to hook this to our users (10.0.0.2- 10.0.0.254) and have them resolve to 12.175.x.66

Then on the DMZ I want to hook our external mail and webservers (10.0.1.1-10.0.1.70) up and use a NAT 1:1 to link these to our 12.175.x.65- 12.175.x.126 range baring the .66 used for the internal users desktops)

I also have dhcp and dns controlled through win2k3 domain controllers.

Easy enough right? Well I can quite get it to work.
on the dmz port I have tried setting up the Nat for say 10.0.1.24 to 12.175.x.116) and then a port forward back but to no avail.
 
I don't know anything about Untangle (I use pfSense), but have you created the firewall rules to allow the traffic you want to come into the NAT? If you set up 1:1 NAT you shouldn't need a port forward.
 
you need to setup the packet filter to allow the inside and DMZ networks to talk to each other. By default the DMZ cannot talk to the inside network.
 
why not post on untangle forums, your likely to get alot more help there,

i got untangle on 3 boxes myself and Captain covered it.
 
Back
Top