hI sangfor team,

We have encountered an issue in the dmz zone the firewall can ping the dmz server but the local pc cant is there any configuration needed.

or what would be the best solutions for this

jerome_itable has solved this question and earned 10 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

Here's a breakdown of the possibilities and some troubleshooting steps you can try:

Possible causes:

    Firewall rules: The Sangfor firewall might have inbound firewall rules blocking traffic from the local PC to the DMZ server.
    Routing: The routing configuration might not be directing traffic from the local PC to the DMZ server correctly.
    DNS resolution: If the local PC is trying to access the DMZ server by hostname, there might be issues with DNS resolution on the local network.
    IP addressing: The local PC and DMZ server might not be using compatible IP addresses or subnet masks.

Troubleshooting steps:

    Check firewall rules: Verify that there are no inbound firewall rules on the Sangfor firewall blocking traffic from the local PC's IP address or subnet to the DMZ server's IP address or subnet. You can check the firewall rules for the DMZ zone or create a specific rule allowing traffic from the local PC to the DMZ server.

    Verify routing: Ensure that the router connected to the local PC and the DMZ server is configured to route traffic between the two networks. This might involve checking routing tables or static routes if necessary.

    Test DNS resolution: Try pinging the DMZ server by its IP address instead of its hostname from the local PC. If the ping by IP address succeeds but not by hostname, there might be an issue with DNS resolution on the local network. Check the DNS settings on the local PC and the DNS server providing resolution for the local network.

    Confirm IP addressing: Make sure the local PC and DMZ server are using compatible IP addresses and subnet masks. They should be on the same subnet or have a route configured to reach each other's subnets.

    Additional checks:
        If you're using VLANs, ensure that the local PC and DMZ server are on the same VLAN or have proper VLAN tagging configured.
        Check for any temporary firewall rules or access control lists that might be blocking traffic.
        Consider consulting the Sangfor firewall documentation or contacting Sangfor support for further assistance.

Best solutions:

The best solution depends on the specific cause of the issue. However, here are some general recommendations:

    Start with the simplest solution first, such as checking firewall rules or DNS resolution.
    Make changes to the network configuration cautiously and document any changes made.
    Test your changes after making them to ensure they resolve the issue without causing any new problems.
    If you're unsure about any of the troubleshooting steps, consult a network administrator or Sangfor support for assistance.
Is this answer helpful?
Newbie517762 Lv5Posted 16 Jan 2024 09:25
  
HiHi,

Are you attempting to configure the NAT? Please refer to the NAT configuration guide below for your reference:
mdamores Posted 16 Jan 2024 12:59
  
not sure if i understand the question correctly but generally there can be two reasons causing this issue. If internet access is working on the DMZ device then check its firewall. it might be blocking outside access
ArsalanAli Lv3Posted 16 Jan 2024 13:17
  
Create a policy for lan Network to access the DMZ servers
also check in System->troubleshooting -> troubleshooting , where your traffic to DMZ zone is blocking
you can also check after put the LAN IP in SOC-> Whitelist (if it start access DMZ zone that means you must create the access policy)
Farina Ahmed Lv5Posted 16 Jan 2024 14:18
  
If you're experiencing a situation where the Sangfor NSF 11000I-A firewall can successfully ping a DMZ server, but local PCs cannot, there may be a configuration issue in the firewall settings. Ensure that the firewall rules governing traffic between the local network and the DMZ zone are correctly configured. Check for any restrictions or misconfigurations that might be preventing communication from the local PCs to the DMZ server. Verify that the necessary ports are open, and there are no conflicting rules impacting outbound traffic from the local network. Also review network topology, routing, and subnet configurations to guarantee proper connectivity. If the issue persists, thorough troubleshooting and examination of logs may be necessary to pinpoint and address the root cause of the problem.
Tayyab0101 Lv2Posted 16 Jan 2024 14:18
  
check in System->troubleshooting.
and check the DMZ traffic
RegiBoy Lv5Posted 16 Jan 2024 14:25
  
heck the firewall rules on both the DMZ server and the local PCs. Ensure that the rules allow incoming ICMP (ping) traffic.
Verify that there are no restrictive rules blocking communication between the local network and the DMZ.
Adam Suhail Lv1Posted 16 Jan 2024 14:55
  
Try to turn off the PC firewall locally. Hope this helps
Apriyanto Lv5Posted 16 Jan 2024 15:36
  
check the route network
Enrico Vanzetto Lv4Posted 16 Jan 2024 16:07
  
Hi,i'm sorry to hear that you’re having trouble accessing the DMZ from your internal network. Here are some possible reasons why this might be happening:

1) Firewall rules: Check if there are any firewall rules that are blocking access to the DMZ from the internal network. You may need to add a rule to allow traffic from the internal network to the DMZ.
2) Routing issues: Ensure that the routing table on your firewall is correctly configured to route traffic between the internal network and the DMZ.
3) Network topology: Verify that the network topology is set up correctly. Ensure that the DMZ is connected to the firewall and that the internal network is connected to the firewall.
4) DNS issues: Check if there are any DNS issues that might be preventing access to the DMZ. Ensure that the DNS server is correctly configured to resolve names in the DMZ.

I hope this helps you resolve the issue. If you need further assistance, please provide more details about your network configuration and the error messages you’re seeing.

I Can Help:

Change

Moderator on This Board

11
7
5

Started Topics

Followers

Follow

1
3
5

Started Topics

Followers

Follow

0
4
5

Started Topics

Followers

Follow

67
20
3

Started Topics

Followers

Follow

3
14
3

Started Topics

Followers

Follow

1
137
3

Started Topics

Followers

Follow

Board Leaders