Dual NICs, Routing Problem



I am using SLES 9 & have a server set up with dual NICs, one has an IP
from my DMZ and the other has the IP of a private network that my
database server is sitting in. I want to be able to make remote ODBC
calls to the DB server from this system to serve up data on the web
sites it is hosting.

My impression of what the problem is leads me to believe it is a
routing issue. To make it easier, let's assume that the network subnets
are the following:

DMZ subnet: 192.1.34.0
Private network: 192.1.36.0

>>From my understanding, I should be able to make the default gateway to
be the gateway of my DMZ network (to respond to web requests from any
host), which is 192.1.34.254 and then make a route that sends all
requests to the '.36' network to the appropriate gateway (192.1.36.1).

So far, I have tried to do this multiple ways according to different
sources on the web, but with no luck on any of them. The easiest way,
which also seems like the way the distribution 'expects' it to be done
is by using YaST. The entry I made was as follows:

Default gateway: 192.1.34.254

Then, in 'Routing Table'...expert configuration section I have:
Destination: 192.1.36.0
Gateway: 192.1.36.1
Netmask: 255.255.255.0
Device: (mac address of eth0...the card with the .36 ip address)

This seems to accomplish nothing for me, as I am not able to
communicate with any nodes on the .36 subnet; and I am not sure why. I
am confident that the issue is not at the switch-level, as if I change
my default gateway to 192.1.36.1, I am able to make remote calls to the
node I need to on the private network (but am unable to serve pages up
to external requests over the .34 ip address).

I would appreciate any help that you can provide. Let me know if there
is any other information that would clarify the issue at hand.


-Tom Kersten

.



Relevant Pages

  • Re: W2K3 domain in DMZ
    ... as each one is the gate to that entire private network. ... > Yes a single domain DMZ ... > Main concerns is getting a DMZ that we can centrally manage and backup ... > server, ...
    (microsoft.public.windows.server.security)
  • RE: DMZ and VPN
    ... > I'm curious as to how it applies to a server providing VPN ... > have one interface on the private network, and the other in a DMZ ...
    (Security-Basics)
  • Re: TS 2008 Web Access with RDP
    ... other machines on the internal network. ... Yes the TS Gateway is on the Server in the DMZ, ...
    (microsoft.public.windows.terminal_services)
  • Re: FE-BE configuration
    ... I think the cheapest and easiest solution would be to install an SMTP ... your single exchange server on your LAN, that way you do not allow inbound ... scanned for viruses or spam (offloading resources to the smtp gateway rather ... you can just install IIS SMTP on the dmz server and harden the OS. ...
    (microsoft.public.exchange2000.admin)
  • Re: Cant access dmz from external network.
    ... And I put a web server on DMZ with ip address ... DMZ NIC ip: XXX.XXX.243.225, 255.255.255.224, Gateway: Blank; ... Understanding the ISA 2004 Access Rule Processing ...
    (microsoft.public.isa.configuration)