LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 09-18-2003, 09:46 PM   #1
piratebiter
Member
 
Registered: Aug 2003
Location: desert
Distribution: RH 8, Debian
Posts: 61

Rep: Reputation: 15
DMZ webserver can have ip aliasing or a 2nd NIC?


I have a three legged firewall up and running (3 NICs , Inet eth0 and ip aliased eth0:0.
My eth2 192.168.1.1 goes to DMZ), i got a DMZ webserver which has currently one NIC (eth0) with ip addr 192.168.1.2.

Goal:
I am working toward the setup for the djbdns (DNS) which will, I guess? have 1 to1 NAT routing thru the firewall Iptables, port 53 etc... I can ipalias on the firewall just fine. I got my second external IP addr ipaliased Inet eth0:0 on the firewall ifconfig, but not routed yet.

I am following a "how to" which shows the DNS going to 192.168.1.3 (on my DMZ network). So, do I add ip aliasing to the webserver NIC too? and create webserver eth0:0 192.168.1.3 and then 1 to 1 DNAT to that from my firewall eth0:0 addr or ?
maybe,
add a second NIC card to the webserver? if so, how would i hook it up... maybe i need another switch for the DMZ network (can do $ if i need to),

right now i use a simple crossover cat 5 cable from the firewall to the webserver. hmm... which way would you try it? ipalias both ends or a switch?

can you even actually ipalias both ends of these cards in the network ? and if so any reason why i wouldn't?

note: this is getting REAL fun! now that the darned works at all after 4-5 weeks... thanks to all who have guided me in this dim light.
P.Biter
 
Old 09-20-2003, 03:37 PM   #2
peter_robb
Senior Member
 
Registered: Feb 2002
Location: Szczecin, Poland
Distribution: Gentoo, Debian
Posts: 2,458

Rep: Reputation: 48
Quote:
I am following a "how to" which shows the DNS going to 192.168.1.3 (on my DMZ network). So, do I add ip aliasing to the webserver NIC too? and create webserver eth0:0 192.168.1.3 and then 1 to 1 DNAT to that from my firewall eth0:0 addr or ?
Quote:
can you even actually ipalias both ends of these cards in the network ? and if so any reason why i wouldn't?
Yes and Yes... and Yes and Yes.
Of course, you could always edit the HowTo and make the dns server 192.168.1.2... then install it in the DMZ server...

All the alias does is allow the NIC to broadcast another ip address in the ARP requests so the network can find the NIC by it'd hardware address (MAC).

The crossover cable is quite fine for just 1 server
 
Old 09-20-2003, 10:14 PM   #3
piratebiter
Member
 
Registered: Aug 2003
Location: desert
Distribution: RH 8, Debian
Posts: 61

Original Poster
Rep: Reputation: 15
excellent, i think I'll do just that for now. I'm eager to move along and see what djbdns can and will do. Thanks much for the encouragement and confirming that it can be done with alias on both ends.
I've got my eye on another Cisco 1548 and when that arrives then it can be even a little bit kewler...
P.Biter
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
2nd NIC? Cornholio Slackware 3 04-25-2005 10:17 AM
1st nic regular FTP, 2nd nic SSH Riselong Linux - Distributions 2 02-02-2004 05:13 PM
Smoothwall, DMZ, Webserver, almost there. Grafbak Linux - Networking 3 07-01-2003 01:05 PM
2nd NIC def1014 Linux - Networking 3 10-23-2002 08:54 AM
need help setting up IPcop-DMZ > webserver greg@athena Linux - Security 1 10-04-2002 07:09 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 07:48 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration