* DMZ suggestion?
@ 2002-06-13 18:55 tbsky
2002-06-13 19:36 ` Antony Stone
0 siblings, 1 reply; 2+ messages in thread
From: tbsky @ 2002-06-13 18:55 UTC (permalink / raw)
To: netfilter
hi:
i use snat for lan(192.168.10.0/24) to dmz(172.16.10.0/24),
but i found that way lan PC will become only one ip to dmz server.
so i think if i can bound another ip (eg: 192.168.10.2) to firewall,
and use dnat for lan to dmz. can anyone suggest which kind of DMZ is
better?
thanks for suggestion!!!
Regards,
tbsky
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: DMZ suggestion?
2002-06-13 18:55 DMZ suggestion? tbsky
@ 2002-06-13 19:36 ` Antony Stone
0 siblings, 0 replies; 2+ messages in thread
From: Antony Stone @ 2002-06-13 19:36 UTC (permalink / raw)
To: netfilter
On Thursday 13 June 2002 7:55 pm, tbsky@greenware.com.tw wrote:
> hi:
> i use snat for lan(192.168.10.0/24) to dmz(172.16.10.0/24),
> but i found that way lan PC will become only one ip to dmz server.
> so i think if i can bound another ip (eg: 192.168.10.2) to firewall,
> and use dnat for lan to dmz. can anyone suggest which kind of DMZ is
> better?
Why do NAT at all between internal LAN and DMZ ?
Why not just route packets with no NAT involved, and allow the ones you want,
block the ones you don't... ?
Antony.
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2002-06-13 19:36 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2002-06-13 18:55 DMZ suggestion? tbsky
2002-06-13 19:36 ` Antony Stone
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox