From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Wagner" Subject: Can someone help me to configure my DMZ? Date: Fri, 15 Aug 2003 16:22:40 -0300 Sender: netfilter-admin@lists.netfilter.org Message-ID: <002a01c36362$98b74bc0$0e021b0a@WAGNERGC> Reply-To: Mime-Version: 1.0 Content-Type: multipart/mixed; boundary="----=_NextPartTM-000-3d375bd1-1364-4037-83a8-73bf095e44ad" Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: netfilter@lists.netfilter.org This is a multi-part message in MIME format. ------=_NextPartTM-000-3d375bd1-1364-4037-83a8-73bf095e44ad Content-Type: multipart/alternative; boundary="----=_NextPart_000_002B_01C36349.736A13C0" ------=_NextPart_000_002B_01C36349.736A13C0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 7bit Hello, I'm new to iptables and i'll have to configure my DMZ like this: ______________________ | | | INTERNET | |_____________________| | | STATIC IP (200.X.X.X - ETH0) _________|______________ STATIC IP | FIREWALL | (192.168.0.1 - ETH2) | RED HAT 9 | ______________| WEB SERVER (APACHE) |__________________________ | | DNS SERVER (BIND) | | | | FTP SERVER | STATIC IP (10.0.0.1 - ETH1) | | |________________________| | | | STATIC IP (10.0.0.2 - ETH0) | ______________|_________ | | DMZ (ONE MACHINE) | | STATIC IP (192.168.0.2) | RED HAT 9 | _____|_________________________ | WEB SERVER (APACHE) | | INTERNAL NETWORK | | MAIL SERVER (QMAIL) | | (ONE MACHINE - WINDOWS XP) | |________________________| |______________________________| I've designed this topology, so if there is a mistake in it please corret me. The firewall machine has 3 net cards. The rules are as follows: Outside people can access the WEB, DNS and FTP servers in the firewall. Outside people can access the WEB and MAIL server on the DMZ. Internal network people can access the WEB, DNS, FTP and MAIL in the DMZ and in the INTERNET. Can someone help me configure IPTABLES to meet this requirement cause i am new to iptables. Thanks a lot in advance, Wagner. ------=_NextPart_000_002B_01C36349.736A13C0 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
Hello,
 
I'm = new to iptables=20 and i'll have to configure my DMZ like this:
 
       &nbs= p;            = ;            =    =20 ______________________
       &nbs= p;            = ;            =    =20 |            =             &= nbsp;           &n= bsp;|
       &nbs= p;            = ;            =    =20 |         INTERNET &nbs= p;         =20 |
       &nbs= p;            = ;            =    =20 |_____________________|
       &nbs= p;            = ;            =             &= nbsp;      =20  |
       &nbs= p;            = ;            =             &= nbsp;       =20 |  STATIC IP (200.X.X.X - ETH0)
       &nbs= p;            = ;            =      _________|______________
STATIC = IP            = ;        =20 |           FIREWA= LL            = ;=20  |
(192.168.0.1 -=20 ETH2)     =20 |          RED HAT=20 9       &nbs= p;       |
       &nbs= p;   ______________| =20 WEB SERVER (APACHE) |__________________________
       &nbs= p;   |        &nbs= p;            = ;  =20 |  DNS SERVER (BIND)       =20 |            =             &= nbsp;           &n= bsp;       =20 |
       &nbs= p;   |        &nbs= p;            = ;  =20 |  FTP=20 SERVER           &= nbsp;       |  STATIC=20 IP (10.0.0.1 - ETH1)   |
       &nbs= p;   |        &nbs= p;            = ;  =20 |________________________|        = ;            =             &= nbsp;           =20 |
       &nbs= p;   |        &nbs= p;            = ;            =             &= nbsp;           &n= bsp;           &nb= sp;           &nbs= p;            = ;            =       =20 | STATIC IP (10.0.0.2 - ETH0)
       &nbs= p;   |        &nbs= p;            = ;            =             &= nbsp;           &n= bsp;           &nb= sp;           &nbs= p;       ______________|_________ = ;   =20
       &nbs= p;   |        &nbs= p;            = ;            =             &= nbsp;           &n= bsp;           &nb= sp;           &nbs= p;     =20 |     DMZ (ONE MACHINE)   =20 |
       &nbs= p;   |     STATIC=20 IP=20 (192.168.0.2)          =             &= nbsp;           &n= bsp;           &nb= sp;=20 |            = RED HAT=20 9            =  |
   _____|______________________= ___           &nbs= p;            = ;            =       =20 |  WEB SERVER (APACHE) |
   |  INTERNAL=20 NETWORK           =       |      =             &= nbsp;           &n= bsp;           =20 |  MAIL SERVER (QMAIL)     = |  =
   |  (ONE MACHINE - = WINDOWS=20 XP) |          &nb= sp;           &nbs= p;            = ;       =20 |________________________|        = ;     
  =20 |______________________________|       = ;            =        =20
 
I've = designed this=20 topology, so if there is a mistake in it please corret me. The firewall = machine=20 has 3 net cards.
 
The = rules are as=20 follows:
 
Outside people can=20 access the WEB, DNS and FTP servers in the firewall.
Outside people can=20 access the WEB and MAIL server on the DMZ.
 
Internal network=20 people can access the WEB, DNS, FTP and MAIL in the DMZ and in the=20 INTERNET.
 
Can = someone help me=20 configure IPTABLES to meet this requirement cause i am new to=20 iptables.
 
Thanks = a lot in=20 advance,
Wagner.
------=_NextPart_000_002B_01C36349.736A13C0-- ------=_NextPartTM-000-3d375bd1-1364-4037-83a8-73bf095e44ad--