Re: [opensuse] SuSEfirewall2: unable to connect to DMZ from behind NAT



Running bind on the firewall it would resolve DNS requests for
http://www.rowansweb.com/ coming from an internal zone to
the DMZ machine.

Whereas someone outside your network would simply
get pointed to your external IP, and the firewall would route
it to the DMZ.


I don't think it's a DNS issue, our DNS server is running on the
internal network (windows). If I try to connect using the IP it's a no
go. For some reason however I can connect to my ext:zone. I tried
changing my dmz interface to an ext:zone but no luck. see config
below.


192.168.1.0/24(masq)zone:int (eth0)-------[f/w ]----108.***.***.60
(eth2) zone:ext

[box]-----68.***.***.234(eth1) zone:dmz

for some reason my masq net cannot connect to eth1 doesn't matter if
it's zone:ext or zone:dmz

--
The general who advances without coveting fame and retreats without
fearing disgrace, whose only thought is to protect his country and do
good service for his sovereign, is the jewel of the kingdom.
- Sun Tzu
--
To unsubscribe, e-mail: opensuse+unsubscribe@xxxxxxxxxxxx
For additional commands, e-mail: opensuse+help@xxxxxxxxxxxx



Relevant Pages

  • Re: [fw-wiz] Rationale of the great DMZ
    ... >DMZ and its implied security has changed. ... Network activity wouldn't ... >necessarily begin from the DMZ and be tunneled in to the internal network. ... >Commonly SSL accelerators terminate the SSL end point prior to the ...
    (Firewall-Wizards)
  • Re: Firewall and DMZ topology
    ... attacker cannot spread his influence across the network. ... If the DMZ resides between the public Internet and the ... Should the DMZ be behind the LAN and not split off at the firewall, ... > The Gartner Group just put Neoteris in the top of its Magic Quadrant, ...
    (Security-Basics)
  • RE: 504 Proxy timeout only with SSL traffic
    ... the DMZ network is considered External to the ... this may have an effect when you access the DMZ. ... And can access all other HTTPS sites on the internet? ... that there may be something wrong with the proxy engine on the ISA, ...
    (microsoft.public.isa)
  • RE: SUS server
    ... Where in my network should I place the SUS server? ... Everything inside my network can talk to the DMZ, ... SurfControl E-mail Filter for SMTP & Exchange leverages multiple layers of ...
    (Focus-Microsoft)
  • Ang: RE: Firewall and DMZ topology
    ... Network Engineer ... Subject: Firewall and DMZ topology ... > The Gartner Group just put Neoteris in the top of its Magic Quadrant, ...
    (Security-Basics)