LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 02-24-2003, 02:30 PM   #1
sheryco
Member
 
Registered: Feb 2003
Location: FTWorth, TX
Distribution: Gentoo, Debian, CentOS, FreeBSD, NetBSD & OpenBSD
Posts: 55

Rep: Reputation: 15
Lightbulb DMZ on Smoothwall


I'm planning to setup a dmz on my smoothwall box but i'm confused on what IP range to use. I'm thinking [ correct me if i'm wrong ] of two options : first

1] red => dhcp from ISP
2] green => say 192.168.1.1
3] orange => say 192.168.2.1

second
1] red => static IP say 88.321.88.2
2] green=> say 192.168.1.1
3 ] orange => say 192.168.2.1 or 88.321.89.1

which option is best configuration for a web server / ftp server on dmz . All suggestions welcomed.
If I go Static on smoothwall do have to create all the routing procedure myself?
 
Old 02-28-2003, 05:57 AM   #2
peter_robb
Senior Member
 
Registered: Feb 2002
Location: Szczecin, Poland
Distribution: Gentoo, Debian
Posts: 2,458

Rep: Reputation: 48
For the first option you will need to use one of the dynamic dns service companies and port forward into the dmz.

Most people have 1 static external number and use private numbers internally. This is Smoothwall's default configuration.

The routing is handled by the netmask you use.
If you have several static numbers, (more expensive), you can split the groups with a netmask so that the routing knows which interface to pass packets to.
You will need to manually alter the NAT/masquerading tables so that an external number in the dmz does not get changed to the red interface number.

Overall, it's easier with 1 static external number. eg
1] red => static IP say 88.321.88.2
2] green=> say 192.168.1.1
3 ] orange => say 192.168.2.1
 
Old 02-28-2003, 07:52 AM   #3
sheryco
Member
 
Registered: Feb 2003
Location: FTWorth, TX
Distribution: Gentoo, Debian, CentOS, FreeBSD, NetBSD & OpenBSD
Posts: 55

Original Poster
Rep: Reputation: 15
Talking

How do i go about using the dynamic dns and is it also possible to use an internal Dns server to do the job instead of Dynamic dns.

Thank you very much for your input.

Last edited by sheryco; 02-28-2003 at 07:55 AM.
 
Old 02-28-2003, 09:25 AM   #4
peter_robb
Senior Member
 
Registered: Feb 2002
Location: Szczecin, Poland
Distribution: Gentoo, Debian
Posts: 2,458

Rep: Reputation: 48
Start at www.dyndns.org

And Yes to your question !
 
Old 02-28-2003, 12:57 PM   #5
sheryco
Member
 
Registered: Feb 2003
Location: FTWorth, TX
Distribution: Gentoo, Debian, CentOS, FreeBSD, NetBSD & OpenBSD
Posts: 55

Original Poster
Rep: Reputation: 15
Thumbs up

Another question please bear with me.
Will class C IP range affect dns resolution to domain if someone else on the internet is using the same Ip address? say i use 192.168.8.9 with people.city.com then some else has the same address but different domain. Will it make no difference.

Again thank you for replying.
 
Old 02-28-2003, 01:54 PM   #6
peter_robb
Senior Member
 
Registered: Feb 2002
Location: Szczecin, Poland
Distribution: Gentoo, Debian
Posts: 2,458

Rep: Reputation: 48
The class A B & C addresses aren't used for internet addresses...
Only for internal networks.
 
Old 02-28-2003, 04:29 PM   #7
sheryco
Member
 
Registered: Feb 2003
Location: FTWorth, TX
Distribution: Gentoo, Debian, CentOS, FreeBSD, NetBSD & OpenBSD
Posts: 55

Original Poster
Rep: Reputation: 15
So that means if I want to have a webserver on my dmz i use internet address other than class A, B & C? If that is so then i must reconfigure my whole dmz network with internet new internet addresses. If that is true then i've messed my whole weekend.
 
Old 03-03-2003, 07:15 AM   #8
peter_robb
Senior Member
 
Registered: Feb 2002
Location: Szczecin, Poland
Distribution: Gentoo, Debian
Posts: 2,458

Rep: Reputation: 48
No no,
as I said in my first post, It's overall easier to use a private address in the DMZ.
This is Smoothie's default...
For Smoothwall 1.0, port forward port 80 to the chosen ip number in the DMZ and add an external access for all ip's on port 80.
For Smoothwall 2 beta, just do the port forwarding.

You can give the web server any number in the ip range for the DMZ, so long as you port forward to it.
Saves having to have hundreds of expensive external numbers.
 
Old 03-03-2003, 11:34 AM   #9
sheryco
Member
 
Registered: Feb 2003
Location: FTWorth, TX
Distribution: Gentoo, Debian, CentOS, FreeBSD, NetBSD & OpenBSD
Posts: 55

Original Poster
Rep: Reputation: 15
Phew i had thought on giving up on webserving idea. Though i have not changed my network yet i try it again. Thanks a lot for your help. Thank you so much.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
DMZ-fli4l-smoothwall-nomachine saavik Linux - Networking 4 09-09-2005 02:01 AM
SmoothWall DMZ: problems with DHCP (i think!!??) jme Linux - Networking 8 03-12-2004 06:53 AM
smoothwall dmz bradyc Linux - Newbie 2 11-04-2003 04:00 PM
Smoothwall, DMZ, Webserver, almost there. Grafbak Linux - Networking 3 07-01-2003 01:05 PM
Smoothwall DMZ config AnotherNewbie Linux - Networking 2 06-09-2002 03:29 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 05:43 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration