Networking Forums

Networking Forums > Computer Networking > Windows Networking > 2 Nics in Windows 2003 server one private one public- odd issue

Reply
Thread Tools Display Modes

2 Nics in Windows 2003 server one private one public- odd issue

 
 
=?Utf-8?B?TWljazI3Njc=?=
Guest
Posts: n/a

 
      11-22-2004, 03:57 PM
2 Nics in Windows 2003 server one private one public- odd issue

I am at a new client who has A windows 2003 server acting as their default
gateway with 2 Nics. One nic is private and plugs into hub, one is public
and plugs into router. There is no firewall. There is one https web site
that no workstation can get to, but from the dual NIC server you can get
there. It is not a DNS issue I have ruled that out. When I have RDC
connection to server I can browse to it. It has to have something to do with
the two NICs and the server acting as a router. All workstations point to
the Dual NIC server private IP for DG. Does anyone have any idea where in
the server I could look to see what is going on I also connected to other
https sites OK. (E-Mail Removed)
 
Reply With Quote
 
 
 
 
Phillip Windell
Guest
Posts: n/a

 
      11-22-2004, 09:12 PM
"Mick2767" <(E-Mail Removed)> wrote in message
news:8B82C9CF-43ED-49BA-9A43-(E-Mail Removed)...
> 2 Nics in Windows 2003 server one private one public- odd issue
>
> I am at a new client who has A windows 2003 server acting as their default
> gateway with 2 Nics. One nic is private and plugs into hub, one is public
> and plugs into router. There is no firewall.


Might not be true. If this is a Cable or DSL connection then the "router"
really isn't a router, but is actually a NAT Box,...which effectively makes
it a "firewall". Now we could all argue all day as to how good a firewall
that makes,...but none-the-less it would be functionally a "firewall"
because machines behind any NAT Device are not directly exposed to the
Internet, except for 1-to-1-NAT situations.

> There is one https web site
> that no workstation can get to, but from the dual NIC server you can get
> there.


Why does the server have two Nics? Are they running RRAS/NAT on the box?
This would create two "firewalls" because it would also be a NAT
Device,...so now you would have two firewalls when you thought you have none
and you would most likely have a Back-to-Back DMZ between the Server and the
"router".

> the Dual NIC server private IP for DG. Does anyone have any idea where in
> the server I could look to see what is going on I also connected to other
> https sites OK.


Does the Server run any type of "proxying" service on it? Are their proxy
settings in the Client machine's browser? Does the https site run on some
port other than 443? If the answer to these three questions are all
"yes",..then that is your problem. Most proxy server sytems are hardcoded to
allow https *only* on port 443 due to the security risk of running https on
a non-standard port. The Server itself may get to the site because it may
not have to use the "proxying services" that the clients are required to
use.

The relevant portion of the following article/link is this paragraph:

"Security Considerations
CONNECT is really a lower-level function than the rest of the HTTP methods,
kind of an escape mechanism for saying that the proxy should not interfere
with the transaction, but merely forward the data. This is because the proxy
should not need to know the entire URI that is being accessed (privacy,
security), only the information that it explicitly needs (hostname and port
number). Due to this fact, the proxy cannot verify that the protocol being
spoken is really SSL, and so the proxy configuration should explicitly limit
allowed connections to well-known SSL ports (such as 443 for HTTPS, 563 for
SNEWS, as assigned by the Internet Assigned Numbers Authority)."

Tunneling SSL Through a WWW Proxy
http://muffin.doit.org/docs/rfc/tunneling_ssl.html



 
Reply With Quote
 
Alan D.
Guest
Posts: n/a

 
      11-24-2004, 04:35 PM
Are they using Routing and Remote Access or ICS?

A friend of mine uses that setup with Routing and Remote Access and he has
never had any trouble with HTTPS.

Alan

"Mick2767" <(E-Mail Removed)> wrote in message
news:8B82C9CF-43ED-49BA-9A43-(E-Mail Removed)...
>2 Nics in Windows 2003 server one private one public- odd issue
>
> I am at a new client who has A windows 2003 server acting as their default
> gateway with 2 Nics. One nic is private and plugs into hub, one is public
> and plugs into router. There is no firewall. There is one https web site
> that no workstation can get to, but from the dual NIC server you can get
> there. It is not a DNS issue I have ruled that out. When I have RDC
> connection to server I can browse to it. It has to have something to do
> with
> the two NICs and the server acting as a router. All workstations point to
> the Dual NIC server private IP for DG. Does anyone have any idea where in
> the server I could look to see what is going on I also connected to other
> https sites OK. (E-Mail Removed)



 
Reply With Quote
 
Joćo Ribeiro
Guest
Posts: n/a

 
      11-24-2004, 08:56 PM
Hi there.
I don't know which kind of http server are you running on the Server 2003,
but if it's a IIS, you can start by check to which IP addresses is it
listening to.
I think that the server is only listening on the NIC with the public IP, and
that's why you can't access the server from your local area network.
Go look in the properties of the web site to check that it is listening on
all ip addresses.
Best regards,
Joćo Ribeiro


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Dual NICs on Server 2003 issue PGPhantom Windows Networking 8 11-29-2006 10:54 PM
No logon server available - Windows 2003 Trust Issue? NS Issue? newsgroups.jd@gmail.com Windows Networking 15 08-21-2006 07:38 PM
setup windows 2003 server as router between 2 private LANs Wing Windows Networking 5 02-02-2006 12:45 AM
[networking] Online Public Chat Tomorrow: TCP/IP in Windows Server 2003 SP1 and Windows XP SP2 Deepak Bansal [MS] Windows Networking 0 06-28-2005 10:30 PM
[networking] Online Public Chat Tomorrow: TCP/IP in Windows Server 2003 SP1 and Windows XP SP2 Deepak Bansal [MS] Windows Networking 0 06-28-2005 10:29 PM



1 2 3 4 5 6 7 8 9 10 11