DS10, dual NICs to both LAN and DMZ of a firewall; doable?
From: Rich Jordan (jordan_at_ccs4vms.com)
Date: 04/30/04
- Next message: John Brandon: "Re: Normal operating temerpature for ES40"
- Previous message: rok_at_nuk.uni-lj.si: "Re: strange disk status"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Date: 30 Apr 2004 14:46:51 -0700
We have an installed DS10 (VMS V7.3-2, TCPIP V5.4) running custom
apps. Its on a NAT'ed LAN behind a firewall that also provides a DMZ
port. All access to the Alpha is from the LAN (or effectively so
through VPN tunnels) except for inbound/outbound SMTP; the Alpha is
the public email server for the domain and has a corresponding hole in
the firewall for port 25 to it.
We need to run a webserver (HPSWS) providing public, but fairly static
info (no CGI, PHP, yadayada) on the Alpha. We can open up port 80 on
the firewall and direct it to the current LAN port on the Alpha,
obviously, and we've had zero problems doing so at other locations
with the same firewall box; no security issues. However I was
wondering if there is any way (or any benefit) to use the second
ethernet port with an available public address hooked up to the DMZ on
the firewall. The DS10 would NOT be set up as a router between the
two interfaces.
I'm not sure this can work, since essentially you'd have two different
routing tables, and/or the need to tell services to use a different
default route for one interface than for the other. I'm still reading
through the TCPIP V5.4 docs, but I don't think that the capability is
available. We can tell each of the other services (SMTP, Telnet, etc)
to only accept connections on the primary interface, while leaving
HPSWS working on both with the set service/address command, though I
dislike doing that with the 'standard' services. Alternatively we
could tell the standard services to reject connections from addresses
outside the LAN and VPN connected sites, while HPSWS accepts them all,
but the routing issues would remain either way.
So I don't think its possible. But just in case I'm wrong, input
would be appreciated.
Rich Jordan
CCS
- Next message: John Brandon: "Re: Normal operating temerpature for ES40"
- Previous message: rok_at_nuk.uni-lj.si: "Re: strange disk status"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Relevant Pages
|