Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Antony Stone <Antony@Soft-Solutions.co.uk>
To: netfilter@lists.netfilter.org
Subject: Re: Problem behind my DMZ
Date: Thu, 8 Jan 2004 17:53:06 +0000	[thread overview]
Message-ID: <200401081753.06528.Antony@Soft-Solutions.co.uk> (raw)
In-Reply-To: <Law9-F95jyNQD9Y7j8J00010259@hotmail.com>

On Thursday 08 January 2004 5:46 pm, Martin Leduc wrote:

> >So where are the local client machines?
>
> No one, it's my dedicate server network.  My server are on a metal box with
> one RJ-45 cable from my ISP.  That's it!

> Example:
>
> My Server 1 (192.168.0.2) tried to send Email to abcd.com.  abcd.com are
> resolved by my internal DNS server.  The MX of the domain abcd.com is
> 20.0.0.4, but this address is, from the server 1 point of view my Firewall.
> So I lost the email.

Okay, so what I was calling your "client machines" are actually just the other 
servers on your network.

In this case if you want to continue using NAT then I cannot see an 
alternative solution to split DNS, so that machines within your network 
receive DNS replies containing the private addresses, and machines outside 
your network receive the public addresses.

If on the other hand you use the suggestion of putting genuine public IPs onto 
your servers (and Ramin Dousti's detailed answer is definitely the best 
solution given your network topology - mine assumed you might want other 
public IPs for some other purpose, but with only one internal network this is 
obviously not the case) then everyone (internal and external) will use public 
IPs and the problem goes away.

Regards,

Antony.

-- 
In Heaven, the police are British, the chefs are Italian, the beer is Belgian, 
the mechanics are German, the lovers are French, the entertainment is 
American, and everything is organised by the Swiss.

In Hell, the police are German, the chefs are British, the beer is American, 
the mechanics are French, the lovers are Swiss, the entertainment is Belgian, 
and everything is organised by the Italians.

                                                     Please reply to the list;
                                                           please don't CC me.



  reply	other threads:[~2004-01-08 17:53 UTC|newest]

Thread overview: 20+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-01-08 17:46 Problem behind my DMZ Martin Leduc
2004-01-08 17:53 ` Antony Stone [this message]
  -- strict thread matches above, loose matches on Subject: below --
2004-01-12 12:08 Martin Leduc
2004-01-10 13:26 Martin Leduc
2004-01-10 12:55 Martin Leduc
2004-01-09  9:54 Martin Leduc
2004-01-09 10:57 ` Antony Stone
2004-01-09 15:26 ` Ramin Dousti
2004-01-09  2:19 Martin Leduc
2004-01-09  4:14 ` Ramin Dousti
2004-01-08 17:12 Martin Leduc
2004-01-08 17:22 ` Antony Stone
2004-01-08 15:53 Martin Leduc
2004-01-08 16:16 ` Antony Stone
2004-01-08 18:10   ` Ramin Dousti
2004-01-08 17:17     ` Antony Stone
2004-01-08 19:18       ` Ramin Dousti
2004-01-08  0:19 Martin Leduc
2004-01-08  2:27 ` Chris Brenton
2004-01-08 16:31   ` Michael Gale

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200401081753.06528.Antony@Soft-Solutions.co.uk \
    --to=antony@soft-solutions.co.uk \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox