dslreports logo
 
    All Forums Hot Topics Gallery
spc
uniqs
93

Brano
I hate Vogons
MVM
join:2002-06-25
Burlington, ON
(Software) OPNsense
Ubiquiti UniFi UAP-AC-PRO
Ubiquiti NanoBeam M5 16

1 edit

Brano to deancollinsb

MVM

to deancollinsb

Re: WAN to ANY

OK man, apples and oranges. You're talking about Layer 7 application gateway also known as reverse proxy server. You can still have this same setup with USG firewall in front of it, nothing is changing.
You can use the SBS for reverse proxy or alternatively Nginx or Apache in reverse proxy mode.

Anav
Sarcastic Llama? Naw, Just Acerbic
Premium Member
join:2001-07-16
Dartmouth, NS

Anav

Premium Member

said by Brano:

OK man, apples and oranges. You're talking about Layer 7 application gateway also known as reverse proxy server. You can still have this same setup with USG firewall in front of it, nothing is changing.
You can use the SBS for reverse proxy or alternatively Nginx or Apache in reverse proxy mode.

PLUS

If all the 30 sites are on one physical server then ZyWall can handle this easily ... basic setup.

If these 30 sites are split between let's say two physical SBS servers then you need a) either two WAN IPs or b) have half the sites that point to 2nd server run on alternate port.

For the DNS approach you'd need deep packet inspection for HTTP and perhaps get it working, but that won't work with HTTPS and you're back to basics.

Okay so I understand, regardless of the number of websites or stuff going in with these servers, they receive all their traffic over a single port?? Thus requiring one port forwarding rule and one firewall rule? If running a second server that port needs to run on a separate port and thus a second port forwarding rule and associated firewall rule?

(or a second public IP (and only fw rule) just for that second server assuming the first one is using the routers WANIP.

I imagine we are talking port 80 for all web traffic, so since most people are not going to be using an alternate port, the second IP is a more logical and obvious choice?

Alternately perhaps................
- can a dydns type address point to the right IP and ALSO CHANGE PORT?? which would be ideal if it could for the second server.

If this was true then it would be too easy to create a port fowarding rule and fw rule for the new port pointing to the second server

OR
Now the zywall can redirect in incoming port to port 80 for the second server without conflict.

ie port 8080 to port 80 for example alleviating need for different port on second server. Since we now have a directed destination LANIP to use for the fw rule there should be no conflict with port 80 going to two different LANIPs.

Obviously the first solution is probably easier but perhaps the second is useful as I do not know how web servers work.

Brano
I hate Vogons
MVM
join:2002-06-25
Burlington, ON

Brano

MVM

You could do the alternate ports but you'd have to tell all your users/clients to use the port ... impractical.
deancollinsb
join:2013-06-09

1 edit

deancollinsb to Anav

Member

to Anav
You cant get more than 1 ip address on Time Warner residential broadband.....so that's not a solution either.