Linux Netfilter discussions
 help / color / mirror / Atom feed
* DMZ suggestion?
@ 2002-06-13 18:55 tbsky
  2002-06-13 19:36 ` Antony Stone
  0 siblings, 1 reply; 2+ messages in thread
From: tbsky @ 2002-06-13 18:55 UTC (permalink / raw)
  To: netfilter

hi:
   i use snat for lan(192.168.10.0/24) to dmz(172.16.10.0/24),
   but i found that way lan PC will become only one ip to dmz server.
   so i think if i can bound another ip (eg: 192.168.10.2) to firewall,
   and use dnat for lan to dmz. can anyone suggest which kind of DMZ is
   better?
   thanks for suggestion!!!

Regards,
tbsky







^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: DMZ suggestion?
  2002-06-13 18:55 DMZ suggestion? tbsky
@ 2002-06-13 19:36 ` Antony Stone
  0 siblings, 0 replies; 2+ messages in thread
From: Antony Stone @ 2002-06-13 19:36 UTC (permalink / raw)
  To: netfilter

On Thursday 13 June 2002 7:55 pm, tbsky@greenware.com.tw wrote:

> hi:
>    i use snat for lan(192.168.10.0/24) to dmz(172.16.10.0/24),
>    but i found that way lan PC will become only one ip to dmz server.
>    so i think if i can bound another ip (eg: 192.168.10.2) to firewall,
>    and use dnat for lan to dmz. can anyone suggest which kind of DMZ is
>    better?

Why do NAT at all between internal LAN and DMZ ?

Why not just route packets with no NAT involved, and allow the ones you want, 
block the ones you don't... ?

 

Antony.


^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2002-06-13 19:36 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2002-06-13 18:55 DMZ suggestion? tbsky
2002-06-13 19:36 ` Antony Stone

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox