From: Tom Eastep <teastep@shorewall.net>
To: Hudson Delbert J Contr 61 CS/SCBN <Delbert.Hudson@LOSANGELES.AF.MIL>
Cc: netfilter@lists.netfilter.org
Subject: Re: Two NICS with same IP and same client IP
Date: Wed, 02 Feb 2005 08:49:42 -0800 [thread overview]
Message-ID: <420104A6.6080308@shorewall.net> (raw)
In-Reply-To: <186AC876521E0F46BDE77079A6567FD06F5FBA@la-ncc-ms1nsabb.losangeles.afspc.ds.af.mil>
Hudson Delbert J Contr 61 CS/SCBN wrote:
> tom,
>
> why ?
>
> to what end, this topology ?
>
> please enlightenment as to the value added ?
>
See http://shorewall.net/myfiles.htm for a description of my
firewall/router's environment. In general, I prefer to use Proxy ARP for
a DMZ rather than NAT because it allows DMZ servers to have the same IP
address whether accessed from local or external clients.
The DMZ interface (eth0 in my case) needs an IP address -- what address
to give it? There seem to be two choices:
a) Select an RFC 1918 address in some currently unused network.
b) Use the firewall's external IP address.
By using b), the existing PTR record can serve both interfaces so that
traffic from the firewall to the server appears to come from the correct
host (gateway.shorewall.net).
In general, consider this:
<upstream router -- address A.B.C.x>
|
|
<gateway router -- address A.B.C.y>
|
---------------------------
| | | | | | |
Network A.B.C.0/24
Assume that the upstream router routes A.B.C.0/24 via the gateway router
A.B.C.y.
The gateway router can be configured as follows:
External interface A.B.C.y/32
Host route to A.B.C.x on external interface (no gateway)
Default route via A.B.C.x
Internal interface A.B.C.y/24
Net router to A.B.C.254/24 on Internal interface (no gateway)
So the gateway router only requires one IP address rather than two yet
it is addressable from both sides.
-Tom
--
Tom Eastep \ Nothing is foolproof to a sufficiently talented fool
Shoreline, \ http://shorewall.net
Washington USA \ teastep@shorewall.net
PGP Public Key \ https://lists.shorewall.net/teastep.pgp.key
next prev parent reply other threads:[~2005-02-02 16:49 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2005-02-02 16:26 Two NICS with same IP and same client IP Hudson Delbert J Contr 61 CS/SCBN
2005-02-02 16:49 ` Tom Eastep [this message]
-- strict thread matches above, loose matches on Subject: below --
2005-02-02 22:22 Hudson Delbert J Contr 61 CS/SCBN
2005-02-02 22:29 ` Jason Opperisano
2005-02-02 16:47 Gary W. Smith
2005-02-02 16:51 ` Raphael Jacquot
[not found] ` <27594E8BA9D5CA458F5EF87D88B6B48F019948@pxtvjoexd01.pxt.primeexalia.co m>
2005-02-02 16:57 ` Hervé
2005-02-02 16:57 ` Hervé
[not found] ` <18348031.1107363459685.JavaMail.rct@kale>
2005-02-02 18:41 ` Bob Tellefson
2005-02-02 20:47 ` Hervé
2005-02-02 9:35 Hervé
2005-02-02 9:48 ` Raphael Jacquot
[not found] ` <5172.57.66.65.39.1107338261.squirrel@57.66.65.39>
2005-02-02 10:28 ` Raphael Jacquot
2005-02-02 14:12 ` Jason Opperisano
2005-02-02 14:32 ` Hervé
2005-02-02 14:41 ` Jason Opperisano
2005-02-02 16:53 ` Hervé
2005-02-02 14:44 ` Raphael Jacquot
2005-02-02 16:40 ` Hervé
2005-02-02 16:22 ` Tom Eastep
2005-02-02 20:56 ` Jason Opperisano
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=420104A6.6080308@shorewall.net \
--to=teastep@shorewall.net \
--cc=Delbert.Hudson@LOSANGELES.AF.MIL \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox