* browsing the "network 'hood" from LAN <-> DMZ
@ 2003-12-05 12:12 Knight, Steve
2003-12-05 12:33 ` Chris Brenton
0 siblings, 1 reply; 3+ messages in thread
From: Knight, Steve @ 2003-12-05 12:12 UTC (permalink / raw)
To: netfilter
Hi chaps
I'm sure this is a straightforward and easily answered question. The
environment is:
--$DMZ_NIC- 192.168.1.0/24 mail,DNS,WWW servers
/
INET -ppp0-FW
\
--$LAN_NIC- 192.168.0.0/24 LAN workstations
I'm trying to get the LAN to be able to NBT browse the boxes in the DMZ, but
they won't. I'm permitting all TCP and UDP from LAN to DMZ and back again
... It looks like NetBIOS isn't going to and from eth0-eth1.
Is there some obvious Windows networking rule I'm missing? I've got TCP and
UDP forward to and fro rules for eth0 and eth1 set up...
Any suggestions gratefully received!
Cheers
Steve
-----------------------------------------------------------------------
Information in this email may be privileged, confidential and is
intended exclusively for the addressee. The views expressed may
not be official policy, but the personal views of the originator.
If you have received it in error, please notify the sender by return
e-mail and delete it from your system. You should not reproduce,
distribute, store, retransmit, use or disclose its contents to anyone.
Please note we reserve the right to monitor all e-mail
communication through our internal and external networks.
-----------------------------------------------------------------------
^ permalink raw reply [flat|nested] 3+ messages in thread* Re: browsing the "network 'hood" from LAN <-> DMZ
2003-12-05 12:12 browsing the "network 'hood" from LAN <-> DMZ Knight, Steve
@ 2003-12-05 12:33 ` Chris Brenton
0 siblings, 0 replies; 3+ messages in thread
From: Chris Brenton @ 2003-12-05 12:33 UTC (permalink / raw)
To: Knight, Steve; +Cc: netfilter
On Fri, 2003-12-05 at 07:12, Knight, Steve wrote:
>
> I'm trying to get the LAN to be able to NBT browse the boxes in the DMZ, but
> they won't. I'm permitting all TCP and UDP from LAN to DMZ and back again
> ... It looks like NetBIOS isn't going to and from eth0-eth1.
First off this is a ***BAD*** idea. You've just removed all security a
DMZ can provide and IMHO you are not much better off than if hosted the
servers on your internal network.
Now with all that said, on the internal network edit the lmhosts file
and add an entry for the system(s) on the DMZ. That or you could setup a
WINS server and point all your systems at it.
HTH,
C
^ permalink raw reply [flat|nested] 3+ messages in thread
* RE: browsing the "network 'hood" from LAN <-> DMZ
@ 2003-12-05 13:47 Knight, Steve
0 siblings, 0 replies; 3+ messages in thread
From: Knight, Steve @ 2003-12-05 13:47 UTC (permalink / raw)
To: netfilter
Duh
And again I say Duh. What a spanner.
Thanks for that Chris - I am suitably larted.
S
-----Original Message-----
From: Chris Brenton [mailto:cbrenton@chrisbrenton.org]
Sent: 5 December 2003 12.34
To: Knight, Steve
Cc: netfilter
Subject: Re: browsing the "network 'hood" from LAN <-> DMZ
On Fri, 2003-12-05 at 07:12, Knight, Steve wrote:
>
> I'm trying to get the LAN to be able to NBT browse the boxes in the DMZ,
but
> they won't. I'm permitting all TCP and UDP from LAN to DMZ and back again
> ... It looks like NetBIOS isn't going to and from eth0-eth1.
First off this is a ***BAD*** idea. You've just removed all security a
DMZ can provide and IMHO you are not much better off than if hosted the
servers on your internal network.
Now with all that said, on the internal network edit the lmhosts file
and add an entry for the system(s) on the DMZ. That or you could setup a
WINS server and point all your systems at it.
HTH,
C
.
-----------------------------------------------------------------------
Information in this email may be privileged, confidential and is
intended exclusively for the addressee. The views expressed may
not be official policy, but the personal views of the originator.
If you have received it in error, please notify the sender by return
e-mail and delete it from your system. You should not reproduce,
distribute, store, retransmit, use or disclose its contents to anyone.
Please note we reserve the right to monitor all e-mail
communication through our internal and external networks.
-----------------------------------------------------------------------
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2003-12-05 13:47 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-12-05 12:12 browsing the "network 'hood" from LAN <-> DMZ Knight, Steve
2003-12-05 12:33 ` Chris Brenton
-- strict thread matches above, loose matches on Subject: below --
2003-12-05 13:47 Knight, Steve
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox