LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 12-18-2002, 05:54 PM   #1
ScreeminChikin
Member
 
Registered: Aug 2002
Location: Kansas City
Distribution: Mandrake 9.2 and a couple of RH7.3 Apache servers
Posts: 153

Rep: Reputation: 30
Need help with DMZ configuration on 3com firewall


Here is my setup. I have a roadrunner with a Cisco UBR900 router that is connected to a 3com officeconnect firewall/DMZ. I only have one "live" IP for my entire network. I have set up an Apache web server that I want to put on the DMZ port of my firewall. This is where I'm stumped, does the DMZ need its own live IP? I have read all of the documentation for the firewall but that only served to confuse me further. Anybody with knowledge of these please help me, or suggest other alternatives.

I was under the impression that I could just give my Apache server a valid IP on my private network and then the firewall would just direct all port 80 traffic to the private IP of the server but I dont understand what settings I need to play with to get that to happen.
 
Old 12-18-2002, 07:07 PM   #2
mcleodnine
Senior Member
 
Registered: May 2001
Location: Left Coast - Canada
Distribution: s l a c k w a r e
Posts: 2,731

Rep: Reputation: 45
If the web server is on the same subnet that your lan is on then it's not really a DMZ. My understanding of most SOHO firewalls is that in order for a DMZ to function the participants behind the firewall should have valid _public_ IPs on the same subnet as the 'outside' port of the firewall.

If you're using NAT masquerading then you would need to segment the 'public' servers from your 'private' LAN. A screened subnet can more or less achieve that.
So your net would look something like this
Lan pool would be on 192.168.0.0
NAT dmz would be on 192.168.99.0
Note that in order for these to be effective you need to make sure that you are using forwarding rules (ie: in iptables/chains) to get in/out rather than static routes.


Have a look at http://csrc.nist.gov/publications/ni...10/node58.html

It was the first result from a google search for 'screened subnet example'
 
Old 12-18-2002, 08:57 PM   #3
ScreeminChikin
Member
 
Registered: Aug 2002
Location: Kansas City
Distribution: Mandrake 9.2 and a couple of RH7.3 Apache servers
Posts: 153

Original Poster
Rep: Reputation: 30
Ok...I'm foggy on the valid public IP part. Lets say that my "live" IP is 50.50.50.51, that gets natted and the Ip that I see as my gateway on the inside of my firewall is 50.50.50.52. Now the 50.50.50.52 is a valid public IP and may be somebody elses live IP but that doesnt matter because its not "seen" on the net right? So if I understand this correctly, the web server on the DMZ port will need an ip like 50.50.50.55 that is a valid public ip but it is still not "seen" on the net. The firewall has to be configured to pass port 80 traffic on the 50.50.50.51 live IP to 50.50.50.55 on the DMZ port? Im making alot of assumptions here so please be patient with me. Am I even in the right neighborhood? Right now the server is accessible fron the net but I had to allow port 80 traffic to pass to that server on the inside of my LAN. Im real uncomfortabe about that. I basically want to do the same thing but not have that traffic getting that far into my network.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
dmz in adsl modem/firewall oldi Linux - Networking 1 07-06-2005 08:56 PM
Network with firewall and DMZ justwantin Linux - Networking 11 05-06-2004 04:07 AM
RH 9 Firewall/Router Iptables DMZ Dammas Linux - Software 0 03-30-2004 01:02 AM
gateway(NAT),firewall,server,DMZ andjules Linux - Newbie 2 11-22-2002 08:11 AM
firewall & DMZ Access problem AnotherNewbie Linux - Hardware 0 05-16-2002 04:01 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 02:29 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration