LinuxQuestions.org
Review your favorite Linux distribution.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 06-07-2012, 06:26 PM   #1
duckmanito
LQ Newbie
 
Registered: Jun 2012
Posts: 3

Rep: Reputation: Disabled
Unhappy iptables - three legged topology


Hi everyone, I fight for hours with this, It seems that I don't really understand iptables or something.

Situation:

I'm trying to build a network with this famous three legged disposition, here is my desired topology:

LAN
|
| (eth1)
|
ROUTER ---(vnet0)--- DMZ (httpd, pbx)
|
| (eth0)
|
Internet

In the router I installed an openvz with two containers for the httpd and pbx servers (10.1.1.x)

The LAN net range is 10.0.0.x

The router works as DNS, DHCPD and NAT provider (sorry if I am too obvious with the details)

This is my iptables file: http://pastebin.com/G4KQTQTj

----

My desire is to have this DMZ with some ports open (like 80) to WAN, but with no comunication with the LAN. I will also want to computers on LAN can connect with the DMZ. I tryied a DROP policy for INPUT and FORWARD chain rules but something don't works.

Sorry for my english and thanks in advance!
 
Old 06-07-2012, 09:18 PM   #2
KinnowGrower
Member
 
Registered: May 2008
Location: Toronto
Distribution: Centos && Debian
Posts: 347

Rep: Reputation: 34
Quote:
Originally Posted by duckmanito View Post
My desire is to have this DMZ with some ports open (like 80) to WAN, but with no comunication with the LAN. I will also want to computers on LAN can connect with the DMZ. I tryied a DROP policy for INPUT and FORWARD chain rules but something don't works.
Can you please list/show ip tables rules. It will be good if you can "show" what did you tried and did not work.
 
Old 06-07-2012, 09:20 PM   #3
duckmanito
LQ Newbie
 
Registered: Jun 2012
Posts: 3

Original Poster
Rep: Reputation: Disabled
I posted it:

This is my iptables file: http://pastebin.com/G4KQTQTj
 
Old 06-07-2012, 10:55 PM   #4
duckmanito
LQ Newbie
 
Registered: Jun 2012
Posts: 3

Original Poster
Rep: Reputation: Disabled
Lightbulb

Solved with this rules: http://paste.debian.net/173440/
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
GT-ITM topology kpachopoulos General 1 06-10-2012 12:41 AM
Simulating network topology with iptables WhiteTree Linux - Laptop and Netbook 5 10-22-2009 06:48 PM
Is this network topology available? bambeklis Linux - Networking 6 03-25-2008 03:43 PM
network topology suggestions alc@pone Linux - Networking 3 12-22-2005 11:22 AM
Network Topology chaste Linux - Networking 6 08-06-2002 09:27 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 08:39 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration