LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-08-2005, 08:26 AM   #1
pierre-luc
LQ Newbie
 
Registered: Oct 2004
Location: Montreal
Distribution: Ubuntu
Posts: 25

Rep: Reputation: 15
Port forwarding DMZ


I've configured a firewall placed in front of a local network (workstations) and a DMZ on the other side. Everything works perfectly to forward traffic but a problem still persists. When I try to get access to a server into the DMZ by its public address (gateway's IP) from the local network, it causes an error. I pretend that this occurs because the server get confused with different IPs with the client. My idea on what happens is unprecised... How should I resolve the problem with Iptables ?
 
Old 05-08-2005, 11:16 AM   #2
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
If I understand your problem correctly, I think what you're seeing is the "local DNAT problem". Take a look at the DNAT section of this tutorial, which describes the cause of the problem as well as a solution. To summarize, the client makes a request to the public IP, which gets NATed to the DMZ host, which then sends the reply locally to the client. So the client gets a reply back from the DMZ instead of the public IP and doesn't recognize as part of a valid connection.
 
Old 05-08-2005, 12:06 PM   #3
pierre-luc
LQ Newbie
 
Registered: Oct 2004
Location: Montreal
Distribution: Ubuntu
Posts: 25

Original Poster
Rep: Reputation: 15
Thank you for your reply.

After reading, I think I'm not going to implement the solution proposed in the HOWTO. It would be better to only edit /etc/hosts and put an alias for my website instead of modifing the way connection will be logged with iptables. For a bigger network, an internal DNS could do the job well also.
 
Old 05-08-2005, 08:56 PM   #4
piratebiter
Member
 
Registered: Aug 2003
Location: desert
Distribution: RH 8, Debian
Posts: 61

Rep: Reputation: 15
lan is blind to the DMZ websites

I will read that post real thoroughly and hopefully the DNAT clue will begin to reveal where I don't see the solution yet. Meanwhile, after about a year of living with this??)) tonite @ dinner it dawned on me (have we got a light bulb lite.gif to put here?). I got SAMBA, I got it good, works puurfeectly; it was a nasty messy ridiculously terible beastly whore to install! (piratebiter, don't mince words... tell us how U really feel!) anywho... all I gotta do to "see" the site on Explorer is open Network Places on the Gates~a~Box, go to the www.Server Folder and open the file for the site I wish to view and click the index or some relevant page... comes right up and is a good simulation of what the world sees... sheesh...!
So EZ when U knows how, Pogo. So, I'm still intrigued with solving this the correct way but at least I can mess with the site and do a bit of checking without dropping the firewall each time. Thanks for the link to the fix I'll READ that... but not tonitezzzz
~Piratebiter~ hisself
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
IPCHAINS port forwarding and IPTABLES port forwarding ediestajr Linux - Networking 26 01-14-2007 07:35 PM
Simple Port Forwarding Firewall - not forwarding MadTurki Linux - Security 14 04-09-2006 12:08 PM
port forwarding/DMZ? router acting up, i think? nixel Linux - Networking 2 12-04-2005 11:18 PM
Opening one TCP port from DMZ into LAN aaviad Linux - Security 2 06-17-2005 08:31 AM
proxy arp or forwarding via iPtables for DMZ? piratebiter Linux - Networking 0 08-28-2003 11:34 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:27 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration