Re: Is this a wise configuration?



None wrote:

Here is my plan:
Configure the DSL router to foward the ports needed for the various servers to a single computer. This computer acts as a firewall between the two network zones. The firewall examines the destination port on incoming packets, and based on that, DNAT's the address to the appropriate physical server. (For example, redirect all packets destined to port 80 to 10.0.0.2, and all packets destined for port 21 to 10.0.0.3).

Also, in order to facilitate the "zone separation", this firewall will drop all packets coming from the "server zone", destined to the private LAN, and vice versa.

I will also configure the firewall to SNAT all packets coming from the "server zone", destined to the internet, with the private LAN IP address of the firewall.

Hopefully, this will behave as expected.

What you're describing is basically a DMZ. Look that up in any firewalling HOWTO.

You may also be able to set up your router as a bridge, and then set up your own firewall behind that.

My DSL is set up so that my DSL modem has one IP, and then my firewall has another routable IP on its external interface, but others may be set up so that the modem doesn't have an IP address at all and simply acts as a bridge... It all depends on the setup the ISP is using...

--Yan
.



Relevant Pages

  • Re: CEICW fails at firewall config
    ... Do you or do you not have ISA 2000 or ISA 2004 installed on the SBS server? ... Do you have 2 NICs in the SBS? ... CEICW fails on firewall configuration every time. ... >>> Call to Creating the protected networks access rule returned ok. ...
    (microsoft.public.windows.server.sbs)
  • Re: Recycler security issues on IIS server
    ... > latest upates to the server. ... > like to see the server put behind our firewall, ... other software, install all patches, IISlockdown, URLscan, use the correct ... the procedures you follow may vary depending on your security needs. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Apache 1.3 Problems
    ... Did the server restart at all and if so are the ... >>>Sounds like a firewall issue. ... >> shows any tcp packets at all getting through except when lynx is run ... Can you show us a 'traceroute bbrb-isp.Stanford.EDU' from your machine? ...
    (freebsd-questions)
  • PPPOE xDSL Firewall with IPTABLES
    ... don't know how to modify my firewall to account for this. ... Starts and stops the IPTABLES packet filter \ ... # Kill malformed XMAS packets ... # server/client to server query or response ...
    (comp.os.linux.networking)
  • Re: ISA SERVER NOT STARTING
    ... I delete the nat/basic firewall and stop and started the RRAS an tried to ... There were no critical events in the DNS Server Log in the last 24 hours. ... An error occurred during logon ... Caller User Name: - ...
    (microsoft.public.windows.server.sbs)