Talk About Network

Google





Software > Linux Debian Maint Firewall > Forwarding data
Latest [ Topics | Posts ] Archive Post A New Topic Post a Reply
<< Topic < Post Post 1 of 4 Topic 1587 of 1645
Post > Topic >>

Forwarding data

by Lars <debs@[EMAIL PROTECTED] > Jul 9, 2008 at 07:20 AM

Hi
I have a couple of questions, but first I'll describe my simple setup. I 
got a Debian Etch gateway with two NIC's; eth0 192.168.1.1/24 (LAN), 
eth0:1 192.168.2.1/24 (DMZ), eth1 10.0.0.2 (input from isp router). I've 
pasted part of my firewall script here, http://pastebin.ca/1066314
I 
left out the variables definitions and cut down on all the different
rules.

Q1) When I access my webserver in DMZ from LAN I can't see the source 
address in the webservers log, I only get 192.168.2.1 (DMZ gateway 
address). The same happens vice-versa and it's a problem due to ACL and 
etc. The strange thing is that it used to work, the source address 
appeared, but unfortunately it stopped. I don't know what I've done, 
cause the firewall script is still the same rules.

Q2) I would like have a mail server in DMZ, but for now I only got a 
working smtp-server. Because of sorbs and reverse lookup I'm forced 
relay my mails through my ISP's smtp server and that's no problem as 
long as I only have the smtp-setup. But as soon as I redirect ****t 25 
down to the mail server in DMZ to receive mails Postfix re****t about 
mail loop. That also happens only when I use Postfix for smtp.
I can't see why I can't redirect the ****t. Perhaps cause my ISP answers 
on ****t 25 which redirects to my smtp-server. Am I missing something or 
is there a work-around?

Q3) I always prefer to only open the ****ts I need, but with SopCat 
(video streaming network) I got a "problem". Sopcast connect on 2-3 
specific ****ts, but when it comes to streaming the video it uses from 
****t 32000 and up (as a new connection). What does you normally do in 
those cases, opens all the ****t, cause it makes no real difference?
-- 
/Lars


-- 
To UNSUBSCRIBE, email to debian-firewall-REQUEST@[EMAIL PROTECTED]
 a subject of "unsubscribe". Trouble? Contact
listmaster@[EMAIL PROTECTED]

 




 4 Posts in Topic:
Forwarding data
Lars <debs@[EMAIL PROT  2008-07-09 07:20:11 
Re: Forwarding data
Mark Chong <mark@[EMAI  2008-07-09 08:40:06 
Re: Forwarding data
Lars <debs@[EMAIL PROT  2008-07-09 13:10:09 
Re: Forwarding data
no-from-header-present@[E  2008-07-09 12:50:10 

Post A Reply:
  Go here to Signup

AddThis Feed Button


About - Advertising - Contact - Frequently Asked Questions - Privacy Policy - Terms of Use - Signup

Contact
localhost-V2008-12-19 Fri Jan 9 14:34:09 PST 2009.