All of lore.kernel.org
 help / color / mirror / Atom feed
* Firewalling issue
@ 2006-07-19 10:25 Ross Cameron
  2006-07-19 10:59 ` Sietse van Zanen
       [not found] ` <1153305518.5888.176.camel@sehe-c4.berlin.teles.de>
  0 siblings, 2 replies; 3+ messages in thread
From: Ross Cameron @ 2006-07-19 10:25 UTC (permalink / raw)
  To: netfilter

Hi there list I have the following issue:

I have a IP split setup on one of my Linux boxes (see diagram below), I 
can route and all access is hunky dory,... BUT I want to block access to 
my DMZ'z gateway address from the outside world.
    How do I do this?


+------------+                                       +------------ +
|            |       eth0 +-------------+  eth1      |             |
|  Internet  |============| FW / Router |============| LAN         |
|            |            +-------------+            |             |
+------------+                    || eth2            +------------ +
                                  ||
                                  ||
                                  ||
                                  ||                 +------------ +
                                  |+-----------------|             |
                                  +------------------|    DMZ      |
                                                     |             |
                                                     +------------ +

KEY:
~~~~
eth0   =>   196.x.x.122 / 255.255.255.252
eth1   =>   192.168.x.x / 255.255.255.0
eth2   =>   196.x.x.94  / 255.255.255.240


The Internet needs to be able to see 196.x.x.80 -> 196.x.x.95,... with 
the exception of 196.x.x.94!!!

Everything else is correct and how I need it to be,... I need to know 
how to DROP the packets coming in on eth0 for 196.x.x.94
BUT packets coming in on eth2 for 196.x.x.94 need to be allowed.

Regards,...
Ross Cameron


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2006-07-19 11:09 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-07-19 10:25 Firewalling issue Ross Cameron
2006-07-19 10:59 ` Sietse van Zanen
     [not found] ` <1153305518.5888.176.camel@sehe-c4.berlin.teles.de>
2006-07-19 11:09   ` Ross Cameron

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.