Linux Netfilter discussions
 help / color / mirror / Atom feed
* IP alias and NAT
@ 2003-01-27 11:31 Jet
  2003-01-27 13:08 ` Cedric Blancher
  0 siblings, 1 reply; 4+ messages in thread
From: Jet @ 2003-01-27 11:31 UTC (permalink / raw)
  To: netfilter

Greeting all,

I just got a strange setup on a client site.
It is a standard network setup, from Internet-> router->firewall->DMZ

The firewall is doing NAT for the servers at DMZ.

The strange part is they always do a IP alias at the firewall external
interface when creating a NAT rule (either preroute or post-route).
If I remove the ip alias, then the connection will never work.

My question is, is this the right setup?

To my understanding, it should be just doing NAT with pre-route or
post-route, and then creating the policy using FORWARD chain.
Using IP alias never seems make sence to me here (what if there is 1000
servers in DMZ).

Anyone have any idea here?


 - Jet
Security Analyst




^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2003-01-30  2:04 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-01-27 11:31 IP alias and NAT Jet
2003-01-27 13:08 ` Cedric Blancher
2003-01-29  4:04   ` Jet
2003-01-30  2:04     ` Joel Newkirk

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox