LinuxQuestions.org
Help answer threads with 0 replies.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 07-03-2007, 10:44 PM   #1
mattsoftnet
Member
 
Registered: Jan 2006
Posts: 120

Rep: Reputation: 15
dmz - different types? what?


I'm guessing there are different types of dmz's. a router dmz and a firewall dmz. a router dmz would forward all ports to one ip by default. a firewall dmz is a nic placed between the trusted and untrusted sides of a firewall. confused? yes, me too.


Code:
   Internet
      |
      |
    Router------- 192.168.2.1 ----- voip
      |      dmz                   192.168.2.2
      |
      |
      | lan
    192.168.3.1
      |
      |
      |--192.168.3.2
      |--192.168.3.3
      |--192.168.3.4

I set up a very nice linux router called brazil firewall. I added a 3rd nic as is required to set up a dmz with the software. I was expecting it to forward all ports to one ip like how linksys routers work, but nope. doesn't work that way. I would like to open up any unused ports to 192.168.2.2 my vonage modem. am I right that the dmz in this linux router s completely different from the dmz in a linksys router?
 
Old 07-04-2007, 01:04 AM   #2
farslayer
LQ Guru
 
Registered: Oct 2005
Location: Northeast Ohio
Distribution: linuxdebian
Posts: 7,249
Blog Entries: 5

Rep: Reputation: 191Reputation: 191
Linksys routers use of the term DMZ is bad.. really bad.. The way the Linksys DMZ works is to forward ALL outside ports to one IP on the internal network. essentially letting anyone from the outside into your internal network, and putting the machine protected by your router right out on the Internet like low hanging fruit...
This is bad, you do not want to use this method ever imho..


A true firewall DMZ is a SEPERATE network segment.
you can control who from the INSIDE private network can access specific ports and systems in the DMZ.
you can control who from the INTERNET public network can access specific ports and systems in the DMZ.

If someone from the outside exploits a machine in the DMZ, they can't use that exploited machine to attack other machines on your internal network, that is why there is a THIRD interface. the DMZ interface.

I would find out what specific ports need to be forwarded from the outside to the VoIP box, and ONLY forward the necessary ports, not ALL ports..
 
Old 07-04-2007, 02:08 AM   #3
mattsoftnet
Member
 
Registered: Jan 2006
Posts: 120

Original Poster
Rep: Reputation: 15
that's what I was thinking, that the term dmz was used wrong by people who don't know what they're talking about. I'll call vonage tech support and ask them about setting up my dmz. right.

I'm gonna hook up the vonage box behind the new linux router for now. if it starts having problems I'll try port forwards and go from there. usually it hates to be behind a firewall, but that linux router is amazing.
 
Old 07-04-2007, 04:08 AM   #4
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1984Reputation: 1984Reputation: 1984Reputation: 1984Reputation: 1984Reputation: 1984Reputation: 1984Reputation: 1984Reputation: 1984Reputation: 1984Reputation: 1984
i oftne see a differentiation by the term "DMZ host" rather than just "DMZ"... still pretty vague though.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
question about iptables (DMZ machine connect to other DMZ machine 's publuic IP) wingmak Linux - Security 1 01-20-2007 04:01 PM
DMZ help... phishman3579 Linux - Networking 19 12-10-2005 12:58 AM
what is dmz blackzone Linux - Networking 3 01-06-2005 05:46 AM
DMZ help phishman3579 Linux - Security 1 07-15-2003 04:47 PM
what is dmz hub cmardhekar Linux - General 1 08-25-2001 09:02 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 10:13 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration