Lost Password? No account yet? Sign up! Why bother?
  • Narrow screen resolution
  • Wide screen resolution
  • Auto width resolution
  • Increase font size
  • Decrease font size
  • Default font size

SmallNetBuilder - Small Network Help

  
Home arrow LAN & WAN arrow LAN & WAN Reviews arrow IPCop Linux Firewall
IPCop Linux Firewall Print E-mail
Daniel Schuhmann   
February 09, 2006

Port Forwarding and Dynamic DNS

A NAT-based router such as IPCop rejects all requests for data that originate from the Internet. While this keeps LAN computers safe from being directly accessed by unknown entities, it presents a problem when you want to allow such requests for say, a web or FTP server. So like commercial NAT-based routers, IPCop can forward requests for specific Internet services to certain machines on your LAN. This is done via a feature called Port Forwarding.

An example of adding a Port Forwarding rule for a webserver is shown in Figure 27. This rule consists of our client's IP address, 192.168.0.168, as the destination IP, as well as the HTTP source port 80 (on the Internet side) and the destination port (on our local client at 192.168.0.168). The field Remark can be used to add a little information about the rule. In our case, this is simply "Webserver".

Adding a Port Forwarding rule

Figure 27: Adding a Port Forwarding rule

After clicking Add, the rule is added to the list in the lower part of the window, and instantly becomes active.

If you want to access clients on your home network remotely, then you're often faced with another problem. Most ISPs assign IP addresses dynamically upon connection, which means that your router (and the services running on any Port-Forwarded servers behind it) will have a different IP address as often as every time the router connects. Fortunately dynamic DNS services provide a way around this problem.

Dynamic DNS service providers offer subdomain names that are kept pointed at the changing IP address of your router. Normally, this requires running a client somewhere on your LAN that detects when your WAN IP address has changed and tells the Dynamic DNS service's servers to grab the new IP address. However, IPCop comes with a built-in client that removes the need to run one on a LAN machine.

Setting up the Dynamic DNS client

Figure 28: Setting up the Dynamic DNS client

Setup involves first creating an account with one of the Dynamic DNS services if you don't already have one. Some Dynamic DNS services, such as www.dyndns.org, are offered free of charge. The service then provides the account information, which is entered into IPCop's interface (Figure 28). IPCop's client can handle operating through an HTTP proxy (the Behind a Proxy checkbox), as some ISP's require, and the Enable Wildcards checkbox handles subdomains.

Finally, IPCop needs to know how to determine its IP address. In most cases, the correct setting is that this is determined by the "red" interface, as shown in Figure 29. The second option only applies if there is a second router between IPCop and the Internet.

Dynamic DNS IP address determination method

Figure 29: Dynamic DNS IP address determination method


Tags: IPCop, Linux, open source, router,

Related Articles:

Centralize Your Network Protection for Free: Copfilter Reviewed
How To: Fixing DNS problems
SmoothWall Express 2.0
How To Securely Web Browse via an SSH Tunnel
m0n0wall Firewall V1.0 - Part 1
 

Most Read

 
 

Over At The Forums

D-Link DNS-323 Mysteries
Hello folks. I'm having issues with my Nas and looking for some thoughts. 1. The 323 gets recognised by Vista as a network device but...

Gigabit Network Help!
I have a gigabit NAS (D-link 323) that I have connected to a D-Link DGS-1005D gigabit switch. I then have my desktop connected to...

Synology DS-209+ review up!!
Looks real good. Now Netgear needs to play catchup and dump that old Infrant CPU for something more modern and powerful!! http://www.trustedreviews.com/networ...ion-DS-209-/p1

Real world NAS vs XP performance
I'm interested in a NAS like the Qnap TS 509 to store a lot of photo image files. We currently use a Windows XP SP3...

FCC OET Filings--November
For a device to utilize the radio spectrum in the United States, the FCC requires hardware manufacturers to apply for the relevant license. These publically-accessible...

Slideshows

NETGEAR ReadyNAS Pro Western Digital ShareSpace QNAP TS-509 Pro D-Link DNS-343 4-Bay Network Storage Enclosure Thecus N3200 RAID 5 NAS D-Link DIR-628 RangeBooster N Dual Band Router More

Win This!

Enter to Win!

You could win a Trendnet TEW-633GR Wireless N Gigabit Router and two TEW-621PC 300Mbps Wireless N-Draft PC Cards

Learn How!

 

Ldr:0.0017409324646, Rct:0.00582599639893, Sky:0.00755000114441, Tlink:0.230002880096, TopPG:0.2301030159, GQV:0.23025894165 seconds to load.