ePlace
Home
Problems
Solutions
- Sample Setup
- Wingate Security
- Local Security
- Applications
- Line Tests
- Security Tests
- Wingate 3.0 FAQ
- Wingate 4 FAQ
Links
Forums
Add Your URL
Disclaimer

Other Languages

email

Sample Setup

Condensed Sample Setup for LAN, Cable Modem, Wingate Proxy, Security 

When setting up a Win2K network using TCP/IP, you will have to use a unique IP address for each machine.  The Internet Assigned Numbers Authority (IANA) has set aside several ranges of IP numbers that can be freely used over private networks (Internet routers will not route them).  Here are the IP address ranges that are designated private: 

10.0.0.0 - 10.255.255.255
172.16.0.0 - 172.31.255.255 
192.168.0.0 - 192.168.255.255

This is a setup used for Wingate 2.1d with 2 NICs on the Wingate Server. Equivalent setups have been used with Wingate Versions 3 and 4. It is assumed that the LAN is setup properly before adding Wingate.
See also: 
Wingate documentation has LAN setup
http://www.wingate.net/secure-wingate.htm (security)
http://www.practicallynetworked.com/

=Definitions=====================================================
IP 192.168.0.1, PC1: MSrv1, WinNT4 SP4 Workstation, Wingate Server
IP 192.168.0.2, PC2: MCli1, Win98 
IP 192.168.0.3, PC3: MCli2, Win95                    
ispModemHost  = ISP-registered user name, e.g., YourName
ispModemDomain= ISP domain name, e.g. isp.xxxxxx.net
isp.b1.c1.d1  = ISP-assigned IP address for cable modem PC
isp.b2.c2.d2  = ISP-assigned IP address for cable modem Gateway
isp.b3.c3.d3  = ISP-assigned IP address for cable modem Primary DNS
isp.b3.c4.d4  = ISP=assigned IP address for cable modem Secondary DNS
Unidentified TCP/IP property entries are defaults    
=MSrv1===========================================================
192.168.0.1 MSrv1|NetworkProperties|IP Address tab
--Adapter #1:  LAN (3C905B-TX)
----Specify an IP Address
------IP Address:......192.168.0.1
------Subnet Mask:.....255.255.255.0
------Default Gateway: (Blank)
--Adapter #2:  Cable Modem (3C905-TX)
----Specify an IP Address
------IP Address:......isp.b1.c1.d1
------Subnet Mask:.....255.255.255.0
------Default Gateway:.isp.b2.c2.d2                    
MSrv1|NetworkProperties|DNS tab (-->NOTE:  Two Host names)
--Host Name:...........ispModemHost (-->NOTE:  Host names differ)
--Domain:..............ispModemDomain
--DNS Service Search Order
----...................isp.b3.c3.d3
----...................isp.b3.c4.d4
--Host Name:...........MSrv1 (-->NOTE:  Host names differ)
--Domain:..............ispModemDomain
--DNS Service Search Order
----...................isp.b3.c3.d3
----...................isp.b3.c4.d4                    
MSrv1|NetworkProperties|WINS Address tab
--Adapter #1:  LAN (3C905B-TX)
----Primary WINS Server:...192.168.0.1
----Seconday WINS Server:..3.168.0.1
--Adapter #2:  Cable Modem (3C905-TX)
----Primary WINS Server:...192.168.0.1
----Seconday WINS Server:..192.168.0.1                  
=MCli1============================================================
192.168.0.2 MCli1|NetworkProperties|IP Address tab 
--Adapter: LAN
----Specify an IP Address
------IP Address:......192.168.0.2
------Subnet Mask:.....255.255.255.0
MCli1|NetworkProperties|DNS tab
--Disable DNS
MCli1|NetworkProperties|Gateway tab
--Installed Gateways:
----192.168.0.1
----192.168.0.3
MCli1|NetworkProperties|WINS Configuration
--Disable WINS Resolution                   
=MCli2============================================================
192.168.0.3 MCli2|NetworkProperties|IP Address tab 
--Adapter: LAN
----Specify an IP Address
------IP Address:......192.168.0.3
------Subnet Mask:.....255.255.255.0
MCli2|NetworkProperties|DNS tab
--Disable DNS
MCli2|NetworkProperties|Gateway tab
--Installed Gateways:
----192.168.0.1
----192.168.0.2
MCli2|NetworkProperties|WINS Configuration
--Disable WINS Resolution                   

==================================================================
Use Wingate Gatekeeper to set these SECURITY parameters
See: http://www.wingate.net/secure-wingate.htm (security)
Select System Policies
--Set Right=User can access services
--Doubleclick Everyone
----Select Location
------Select Specify locations from where this recipient has rights
--------Add 127.0.0.1
--------Add 192.168.0.*
Internet Explorer Properties|Connection (all PCs)
--Connect to Internet using a local area network (Selected)
--Access the Internet using a proxy server (Checked)
----Advanced...
------Type.....Address of proxy to use.Port
------HTTP:....192.168.0.1.............80
------Secure:..192.168.0.1.............80
------FTP:.....192.168.0.1.............80
------Gopher:............................
------Socks:...192.168.0.1.............1080
------Exceptions:
--------127.0.0.1
--------(192.168.0.1:1080)(in Wingate server IE only)


Note.  The Personal Web Server defaults to port 80. If you use the PWS, Note.  The Personal Web Server defaults to port 80. If you use the PWS, resolve a port conflict by changing the WWW Wingate service default
port 80 to port 85 and the corresponding browser ports 80 to 85.

SECURITY REFERENCES
See: Wingate Security and Solutions
Last Updated July 29, 2002 10:21:48 PM