Networking Forums

Networking Forums > Computer Networking > Windows Networking > Network question regarding web server?

Reply
Thread Tools Display Modes

Network question regarding web server?

 
 
JP Breton
Guest
Posts: n/a

 
      11-25-2003, 12:13 PM
Sorry if it is the wrong newsgroup.

I am trying to access a web site : http://cipo.gc.ca
I am getting a page not found.

After contacting the IT departement, here is what they told me:

In your instance, the Connecting IP and the Reported IP do not match. This
often occurs when people are behind firewalls or have networks using NAT
Translation. Unfortunately, it is also a tactic (reporting a different IP
address) used by people who are attacking a website.
Due to Government of Canada guidelines regarding the protection of data
(Protected 'B' data), all inbound web traffic that reports an incorrect IP
address is refused.
In order to use Strategis and the CIPO website, the user will have to
rectify the Reverse DNS Lookup problem that they are experiencing.You need
to resolve this issue by calling you IPS and give them this information or
by contacting your source behind your firewalls.

We do use 2 different IP address (we use NAT with our PIX firewall)

Is this a normal setup for that company?
Do we really need to change our IP address so they are both the same?
Is in it a security risk?

Thanks for any help or feedback

John



 
Reply With Quote
 
 
 
 
Keith W. McCammon
Guest
Posts: n/a

 
      11-25-2003, 12:50 PM
> We do use 2 different IP address (we use NAT with our PIX firewall)
>
> Is this a normal setup for that company?


Yes, this is more than normal, if that's possible.

> Do we really need to change our IP address so they are both the same?


They should be the same. When traffic leaves the PIX from AddrA, the remote
server establishes the connection with this address.

> Is in it a security risk?


No more than usual, when you're connected to the Internet.

Unless you're doing something very screwy with your firewall, it sounds like
someone's taking the reverse lookup to the extreme.


 
Reply With Quote
 
Jeff Cochran
Guest
Posts: n/a

 
      11-25-2003, 03:57 PM
On Tue, 25 Nov 2003 08:13:37 -0500, "JP Breton"
<(E-Mail Removed)> wrote:

>Sorry if it is the wrong newsgroup.
>
>I am trying to access a web site : http://cipo.gc.ca
>I am getting a page not found.
>
>After contacting the IT departement, here is what they told me:
>
>In your instance, the Connecting IP and the Reported IP do not match. This
>often occurs when people are behind firewalls or have networks using NAT
>Translation. Unfortunately, it is also a tactic (reporting a different IP
>address) used by people who are attacking a website.
>Due to Government of Canada guidelines regarding the protection of data
>(Protected 'B' data), all inbound web traffic that reports an incorrect IP
>address is refused.
>In order to use Strategis and the CIPO website, the user will have to
>rectify the Reverse DNS Lookup problem that they are experiencing.You need
>to resolve this issue by calling you IPS and give them this information or
>by contacting your source behind your firewalls.
>
>We do use 2 different IP address (we use NAT with our PIX firewall)
>
>Is this a normal setup for that company?


Sure.

>Do we really need to change our IP address so they are both the same?


No. You need to correct the reverse DNS so it returns the correct
information.

>Is in it a security risk?


It decreases a security risk. It lets the web server know you really
are who you said you were.

Check a DNS group for better specifics, but it's your ISP and/or your
network administrator that need to configure this.

If it's any consolation, from behind a firewall and with a NAT'd
address, I connect just fine to the above site. But my reverse DNS
points to the correct host. In your case, my guess is your ISP has
pointed the reverse DNS to a generic port name on a different domain,
or more possibly has no reverse DNS defined for your IP.

Jeff
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
2003 Server/Exchange Server...move to different subnet question Windows Networking 1 11-17-2006 01:49 PM
NEWB QUESTION: New network w/ server and clients GeekBoy Windows Networking 6 02-09-2006 10:39 PM
AD question about "first DNS server on network" DWalker Windows Networking 9 09-20-2005 05:50 PM
Network connection with proxy server - further question Martin Underwood Home Networking 3 02-13-2005 01:01 AM
General server network question rlampky Windows Networking 1 04-05-2004 04:21 PM



1 2 3 4 5 6 7 8 9 10 11