From: "Wagner" <wagnergc@itautec-philco.com.br>
To: netfilter@lists.netfilter.org
Subject: RES: Can someone help me to configure my DMZ?
Date: Mon, 25 Aug 2003 16:06:18 -0300 [thread overview]
Message-ID: <005901c36b3b$f85442a0$0e021b0a@WAGNERGC> (raw)
In-Reply-To: <20030819173401.25ba135d.arnt@c2i.net>
[-- Attachment #1: Type: text/plain, Size: 2898 bytes --]
Hello,
I'm attaching a new picture and now you can see ecxactly what i've written.
Thanks a lot in advance,
Wagner.
-----Mensagem original-----
De: netfilter-admin@lists.netfilter.org
[mailto:netfilter-admin@lists.netfilter.org]Em nome de Arnt Karlsen
Enviada em: terca-feira, 19 de agosto de 2003 12:34
Para: netfilter@lists.netfilter.org
Assunto: Re: Can someone help me to configure my DMZ?
On Fri, 15 Aug 2003 16:22:40 -0300,
"Wagner" <wagnergc@itautec-philco.com.br> wrote in message
<002a01c36362$98b74bc0$0e021b0a@WAGNERGC>:
> Hello,
>
> I'm new to iptables and i'll have to configure my DMZ like this:
...no, you didn't, because you made your ascii art too wide.
..squeeze it to within 72 characters or less, and repost.
>
> ______________________
> |
|> | INTERNET
|> |_____________________|
> |
> | STATIC IP
> (200.X.X.X - ETH0)
> _________|______________
> STATIC IP | FIREWALL |
> (192.168.0.1 - ETH2) | RED HAT 9 |
> ______________| WEB SERVER (APACHE)
> |__________________________ | DNS
> |SERVER (BIND) ||
> | | FTP SERVER |
> STATIC IP (10.0.0.1 - ETH1) |
> | |________________________|
> |
> |
> | STATIC IP (10.0.0.2 - ETH0)
> |
> ______________|_________
> |
> | DMZ (ONE MACHINE) |
> | STATIC IP (192.168.0.2)
> | RED HAT 9 |
> _____|_________________________
> | WEB SERVER (APACHE) |
> | INTERNAL NETWORK |
> | MAIL SERVER (QMAIL) |
> | (ONE MACHINE - WINDOWS XP) |
> |________________________|
> |______________________________|
>
> I've designed this topology, so if there is a mistake in it please
> corret me. The firewall machine has 3 net cards.
>
> The rules are as follows:
>
> Outside people can access the WEB, DNS and FTP servers in the
> firewall. Outside people can access the WEB and MAIL server on the
> DMZ.
>
> Internal network people can access the WEB, DNS, FTP and MAIL in the
> DMZ and in the INTERNET.
>
> Can someone help me configure IPTABLES to meet this requirement cause
> i am new to iptables.
>
> Thanks a lot in advance,
> Wagner.
>
--
..med vennlig hilsen = with Kind Regards from Arnt... ;-)
...with a number of polar bear hunters in his ancestry...
Scenarios always come in sets of three:
best case, worst case, and just in case.
[-- Attachment #2: dmz.gif --]
[-- Type: application/octet-stream, Size: 22663 bytes --]
prev parent reply other threads:[~2003-08-25 19:06 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2003-08-15 19:22 Can someone help me to configure my DMZ? Wagner
2003-08-19 15:34 ` Arnt Karlsen
2003-08-25 19:06 ` Wagner [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to='005901c36b3b$f85442a0$0e021b0a@WAGNERGC' \
--to=wagnergc@itautec-philco.com.br \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox