11-24-2015 06:13 AM - edited 03-17-2019 05:00 AM
I want to be able to block web admin gui access to the edge server from the internet, and only allow Lan subnets from inside the network.
Is this possible ?
Solved! Go to Solution.
11-24-2015 07:32 AM
That is how it normally works as Services DMZ NIC should be behind firewall and http and https port should not be allowed to it from outisde network.
Are you NATing the LAN2 interface or did you put it on public IP without firewall?
11-24-2015 07:58 AM
Agree with Chris on this, there should be a Firewall which sits between the Exp-E node and the outside world which only permits traffic needed as per the Deployment Guide.
11-24-2015 07:32 AM
That is how it normally works as Services DMZ NIC should be behind firewall and http and https port should not be allowed to it from outisde network.
Are you NATing the LAN2 interface or did you put it on public IP without firewall?
11-25-2015 02:04 AM
sorry, I didn't explain very well. Yes I have 1 nic interface with static Nat and it is in the DMZ of the firewall, Is HTTP and HTTPS protocol only needed for Access? If so I will just block them as suggested
11-25-2015 02:26 AM
HTTP/HTTPS are only needed for management, you may block them together with SSH.
11-25-2015 02:46 AM
many thanks
11-25-2015 02:53 AM
The ports required for MRA to work via Expressway are in the deployment guide.
The recommended configuration is to have a firewall between the Exp-E and the outside world. The default behaviour of a Firewall is to block everything inbound towards the Exp-E including http and https. You then just open the ports required as per the deployment guide for MRA to function.
11-24-2015 07:58 AM
Agree with Chris on this, there should be a Firewall which sits between the Exp-E node and the outside world which only permits traffic needed as per the Deployment Guide.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide