Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 01-10-2011, 03:20 AM
Junior Member
 
Posts: 8
Default Login page from outside firewall.

Hi there

This is my first forum posting here so hope this all makes sense.

I have recently migrated from Desknow to Zimbra Network Edition (6.10) running on an Ubuntu 10.04 LTS server (64bit edition).

We are running a single domain on a single server which has multiple IP addresses on our internal LAN (4 NIC's in the server). The issue we are having is that we can not access the web interface externally. However it does appear to load a completely white page, there are do DNS or browser errors. This has been tried in both IE 6 & 7 & firefox 3.6

Internally from the LAN everything works fine.

I have put as much of our config in as I think is relevant below:

The firewall and external DNS (with our ISP) are configured so that webmail.xxxx.xxx.uk points to an external IP 82.69.xxx.xxx

The firewall is configured to permit traffic on that IP for ports 80 & 7071 and forward them to the internal address of our zimbra server (both http & https, I have also tried opening all firewall ports for an hour and trying but without any success).

The firewall logs show a connection being made and it appears to pass through.

I have looked at both the /var/log/zimbra.log and /opt/zimbra/jetty/log/access_log.date and can not see any reference to an external IP address.

Under the MTA settings I have both the hostname and FQDN as options for managing mail. I have also added the public service host address as the externally configured address (which is the same as the FQDN).

DNS is setup using the existing internal DNS servers, the hosts file is configured as follows:

127.0.0.1 localhost webmail.xxxx.xxx.uk webmail
172.xxx.xxx.xxx webmail.xxxx.xxx.uk webmail


The resolve.conf is configured as follows:

Search domainname
nameserver 172.xxx.xxx.xxx
nameserver 8.8.8.8

The domain is setup to receive and forward mail via our internal anti spam system and the MX records are configured accordingly.

We are able to send and receive email both internally and externally so that appears to be working ok.

I'm not sure if there are any other logs I can look at which may indicate if traffic is being rejected either by the OS or by Zimbra or if there is an item of config I am missing.

Any help would be appreciated.

Many Thanks

Tony
Reply With Quote
  #2 (permalink)  
Old 01-13-2011, 12:34 AM
Special Member
 
Posts: 162
Default

Welcome to the Zimbra community.

First comment: EEEK! You're using HTTP on the public network side?
Second comment: EEEEK!! You're exposing your admin console to the Internet?

Sounds like you just need to close 80 and open 443 (that's how mine's setup). Even if you've got zmtlscontrol set to redirect, I wouldn't recommend having un-encrypted access at all.

Hope that helps.
Reply With Quote
  #3 (permalink)  
Old 01-13-2011, 02:55 AM
Zimbra Consultant & Moderator
 
Posts: 20,315
Default

In addition to the above comments (you really should rethink your security for external connections to the server) your hosts file is incorrect and will cause you problems. Go to the Split DNS article and then read the 'Verify...' section for the format of your hosts file.
__________________
Regards


Bill
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.