Linux Netfilter discussions
 help / color / mirror / Atom feed
* browsing the "network 'hood" from LAN <-> DMZ
@ 2003-12-05 12:12 Knight, Steve
  2003-12-05 12:33 ` Chris Brenton
  0 siblings, 1 reply; 3+ messages in thread
From: Knight, Steve @ 2003-12-05 12:12 UTC (permalink / raw)
  To: netfilter

Hi chaps

I'm sure this is a straightforward and easily answered question.  The
environment is:


              --$DMZ_NIC- 192.168.1.0/24 mail,DNS,WWW servers
             /
INET -ppp0-FW
             \
              --$LAN_NIC- 192.168.0.0/24 LAN workstations


I'm trying to get the LAN to be able to NBT browse the boxes in the DMZ, but
they won't.  I'm permitting all TCP and UDP from LAN to DMZ and back again
...  It looks like NetBIOS isn't going to and from eth0-eth1.

Is there some obvious Windows networking rule I'm missing?  I've got TCP and
UDP forward to and fro rules for eth0 and eth1 set up...

Any suggestions gratefully received!

Cheers

Steve


-----------------------------------------------------------------------
Information in this email may be privileged, confidential and is 
intended exclusively for the addressee.  The views expressed may
not be official policy, but the personal views of the originator.
If you have received it in error, please notify the sender by return
e-mail and delete it from your system.  You should not reproduce, 
distribute, store, retransmit, use or disclose its contents to anyone.
 
Please note we reserve the right to monitor all e-mail
communication through our internal and external networks.
-----------------------------------------------------------------------



^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: browsing the "network 'hood" from LAN <-> DMZ
  2003-12-05 12:12 browsing the "network 'hood" from LAN <-> DMZ Knight, Steve
@ 2003-12-05 12:33 ` Chris Brenton
  0 siblings, 0 replies; 3+ messages in thread
From: Chris Brenton @ 2003-12-05 12:33 UTC (permalink / raw)
  To: Knight, Steve; +Cc: netfilter

On Fri, 2003-12-05 at 07:12, Knight, Steve wrote:
>
> I'm trying to get the LAN to be able to NBT browse the boxes in the DMZ, but
> they won't.  I'm permitting all TCP and UDP from LAN to DMZ and back again
> ...  It looks like NetBIOS isn't going to and from eth0-eth1.

First off this is a ***BAD*** idea. You've just removed all security a
DMZ can provide and IMHO you are not much better off than if hosted the
servers on your internal network.

Now with all that said, on the internal network edit the lmhosts file
and add an entry for the system(s) on the DMZ. That or you could setup a
WINS server and point all your systems at it.

HTH,
C




^ permalink raw reply	[flat|nested] 3+ messages in thread

* RE: browsing the "network 'hood" from LAN <-> DMZ
@ 2003-12-05 13:47 Knight, Steve
  0 siblings, 0 replies; 3+ messages in thread
From: Knight, Steve @ 2003-12-05 13:47 UTC (permalink / raw)
  To: netfilter

Duh

And again I say Duh.  What a spanner.

Thanks for that Chris - I am suitably larted.

S




-----Original Message-----
From: Chris Brenton [mailto:cbrenton@chrisbrenton.org] 
Sent: 5 December 2003 12.34
To: Knight, Steve
Cc: netfilter
Subject: Re: browsing the "network 'hood" from LAN <-> DMZ


On Fri, 2003-12-05 at 07:12, Knight, Steve wrote:
>
> I'm trying to get the LAN to be able to NBT browse the boxes in the DMZ,
but
> they won't.  I'm permitting all TCP and UDP from LAN to DMZ and back again
> ...  It looks like NetBIOS isn't going to and from eth0-eth1.

First off this is a ***BAD*** idea. You've just removed all security a
DMZ can provide and IMHO you are not much better off than if hosted the
servers on your internal network.

Now with all that said, on the internal network edit the lmhosts file
and add an entry for the system(s) on the DMZ. That or you could setup a
WINS server and point all your systems at it.

HTH,
C




.


-----------------------------------------------------------------------
Information in this email may be privileged, confidential and is 
intended exclusively for the addressee.  The views expressed may
not be official policy, but the personal views of the originator.
If you have received it in error, please notify the sender by return
e-mail and delete it from your system.  You should not reproduce, 
distribute, store, retransmit, use or disclose its contents to anyone.
 
Please note we reserve the right to monitor all e-mail
communication through our internal and external networks.
-----------------------------------------------------------------------



^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2003-12-05 13:47 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-12-05 12:12 browsing the "network 'hood" from LAN <-> DMZ Knight, Steve
2003-12-05 12:33 ` Chris Brenton
  -- strict thread matches above, loose matches on Subject: below --
2003-12-05 13:47 Knight, Steve

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox