LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 09-13-2007, 01:16 PM   #1
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Posts: 2,190

Rep: Reputation: 60
Stupid DMZ Networking Question


If I have allowed only certain traffic (IPTABLES) into my DMZ then just those ports should be able to access that specific service on the forwarded device on the DMZ. Ex. TCP 80 VOIP web server on my DMZ. So my question is:

If I am outside my network and lets say I wanted to access port 80 on my DMZ from that outside how does one do that: EX. external_IP:80

I am confused?
 
Old 09-13-2007, 03:44 PM   #2
andrewdodsworth
Member
 
Registered: Oct 2003
Location: United Kingdom
Distribution: SuSE 10.0 - 11.4
Posts: 347

Rep: Reputation: 30
Apart from opening ports to the DMZ and allowing traffic in (and replies back out) you will also have to do DNAT so that any source IP with address of your external IP port 80 gets altered to destination your DMZ server IP port 80.
 
Old 09-13-2007, 08:19 PM   #3
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Posts: 2,190

Original Poster
Rep: Reputation: 60
adding a prerouting statement with DNAT would do that but what I mean is, lets say that everything is ok on the firewall/router then how would I access that service externally?
 
Old 09-14-2007, 11:51 AM   #4
andrewdodsworth
Member
 
Registered: Oct 2003
Location: United Kingdom
Distribution: SuSE 10.0 - 11.4
Posts: 347

Rep: Reputation: 30
I don't think I understand your problem as I just thought you wanted to route something from external IP to DMZ machine. For example if your external IP is 212.23.100.100 and you have DNAT rule to change that to your DMZ machine which is 10.0.0.100, then from the outside you point your application at 212.23.100.100. Is it something else?
 
Old 09-14-2007, 01:08 PM   #5
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Posts: 2,190

Original Poster
Rep: Reputation: 60
I had a major brain fart. I just realized how stupid of a question is was that I really ask. Many thanks
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
To DMZ or not to DMZ. That is the question. MykeV Linux - Networking 6 10-02-2007 01:12 PM
question about iptables (DMZ machine connect to other DMZ machine 's publuic IP) wingmak Linux - Security 1 01-20-2007 04:01 PM
Stupid, stupid question; I lost Klaptop. :( Surfrider Slackware 2 08-31-2005 09:12 PM
stupid networking question thick_guy_9 Slackware 3 07-06-2005 08:11 PM
Stupid Dumb Stupid Question... drigz Linux - Software 3 09-23-2004 03:09 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 11:15 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration