From: alan barrow <aaa.coms.sec@btclick.com>
To: netfilter@lists.samba.org
Subject: a discussion starter i hope.
Date: 09 May 2002 21:11:01 +0100 [thread overview]
Message-ID: <1020975061.20151.16.camel@sarig.internal> (raw)
[-- Attachment #1: Type: text/plain, Size: 1565 bytes --]
I have been using iptables-netfilter for a while and wish to clarify in
my mind for once how to do the following.
Scenario: An iptables firewall has 2 interfaces, which are a public and
a private interface, for simpilicty's sake. Behind the firewall a
service runs which needs to be visible to the world at large in this
case let's start with an easy one http, on port 80.
No problems so far :)
Now behind the firewall are 2 separate servers, each running a web
service and each running on port 80.
1) The question is, with only 1 real world address available to you,
what suggestions do you guy's have as to the configuration required to
make both web servers available on the Internet ? So that incoming port
80 request on the firewall public interface go to the correct server.
2) The same as scenario 1) except you have 2 addresses available but
only one external NIC.
3) Same as 2) except you have 2 NIC's.
The reason for this is the following is that, i wish to understand if
there is a path to this result. I realise there are probably many way's
to skin this cat, and i have tried a few of them, some of you may
already be doing this, but in my experience there seem to be a lot of
pitfall's and consequently the issues i have faced seem to suggest the
following:
Some think it's possible, Some don't, some wish it was possible, many
just say this way, others suggest that way, many just give up.
All in all i would like to take this to the logical conclusion of
getting it working in multiple scenarios securely and effectively.
yours a.r.b.
[-- Attachment #2: Type: text/html, Size: 1903 bytes --]
next reply other threads:[~2002-05-09 20:11 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2002-05-09 20:11 alan barrow [this message]
2002-06-13 16:13 ` a discussion starter i hope Antony Stone
-- strict thread matches above, loose matches on Subject: below --
2002-05-09 22:52 alan barrow
2002-06-13 16:30 ` Nathan Cassano
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1020975061.20151.16.camel@sarig.internal \
--to=aaa.coms.sec@btclick.com \
--cc=netfilter@lists.samba.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.