NAT problem with public network

From: John Angelmo (john_at_veidit.net)
Date: 12/16/04

  • Next message: Milan Obuch: "ath driver - help needed"
    Date: Thu, 16 Dec 2004 11:06:03 +0100
    To: freebsd-net@freebsd.org
    
    

    Hello

    I have a network setup like this:

    xl0: External:213.115.251.220
    xl1: DMZ: 213.115.148.64/28
    xl2: Internal: 192.168.20.0/24

    Now my problem seems to be that I need to get external connection for my
    Internal network but not nating the DMZ

    To simplify it all /etc/natd.conf has this line:
    interface xl0

    and to get nat to work I just use:
    ipfw add divert natd log all from any to any via xl0

    but that would nat all the traffic, how should I do just to use nat for
    my 192.168.20.0/24 network and not the 213.115.148.64/28 network?

    /John
    _______________________________________________
    freebsd-net@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-net
    To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"


  • Next message: Milan Obuch: "ath driver - help needed"

    Relevant Pages

    • Re: [fw-wiz] Rationale of the great DMZ
      ... >DMZ and its implied security has changed. ... Network activity wouldn't ... >necessarily begin from the DMZ and be tunneled in to the internal network. ... >Commonly SSL accelerators terminate the SSL end point prior to the ...
      (Firewall-Wizards)
    • Re: How did they get behind my NAT?
      ... The double NAT setup makes sense, I did not understand that you meant ... A DMZ is a secured network that you use for Public hosts that they don't ... you put your web server in the DMZ network - that would be the LAN ... create filth and put it on the web for any kid to see: ...
      (alt.computer.security)
    • Re: Standard DMZ set-up
      ... Some people don't like to open up things via NAT to their internal ... would only be able to impact other machines in the DMZ. ... then the whole internal network could ...
      (comp.security.firewalls)
    • Re: Help with NAT definition
      ... > I need help with NAT in a CISCO PIX 515E. ... > order to avoid routing the network 192.168.102.0. ... ip nat inside source list 1 interface overload ... As to *why* you would want to undo a DMZ in this manner escapes me ...
      (comp.security.firewalls)
    • Re: Firewall and DMZ topology
      ... attacker cannot spread his influence across the network. ... If the DMZ resides between the public Internet and the ... Should the DMZ be behind the LAN and not split off at the firewall, ... > The Gartner Group just put Neoteris in the top of its Magic Quadrant, ...
      (Security-Basics)