[fw-wiz] Non-NAT Firewall

From: Nathaniel Hall (nathaniel.d.hall_at_gmail.com)
Date: 11/07/05

  • Next message: Adam Greene: "[fw-wiz] medical records, web server, & stateful firewall vs packet filter"
    To: firewall-wizards@honor.icsalabs.com
    Date: Sun, 06 Nov 2005 18:28:03 -0600
    
    

    Alright, this is a bit tough to explain, so I will try my best.

    I am currently running a CheckPoint-NG firewall with three interfaces.
    Interface 1 goes to DMZ 1 (public IP addressing and Internet facing),
    interface 2 goes to DMZ 2 (public IP addressing) and interface 3 goes to
    the internal network (private IP addressing). The CheckPoint FW does
    not peform NAT. That allows me to review logs of servers in DMZ 1
    without having to figure out what internal IP as NATed.

    Now, for my problem. I would like to be able to have the same
    functionality using NetFilter, but I have not been able to figure out
    how to do this without masquerading or using DNAT and SNAT. Any ideas?

    -- 
    Nathaniel Hall, GSEC GCIA
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    

  • Next message: Adam Greene: "[fw-wiz] medical records, web server, & stateful firewall vs packet filter"

    Relevant Pages

    • Re: Queue Drops
      ... >> not on the serial interfaces. ... >> In one of the sites I have Internet T1s to a different ISP that uses PPP ... > encapsulation on the links and I do not have any problems with queue drops. ... Worry about the internal traffic hitting the router ...
      (comp.dcom.sys.cisco)
    • Re: SBS 2003 Connects to Internet/Clients Do Not
      ... I've gone thru the Internet Wizard ... With SBS 4.5, I was very comfortable setting up the Proxy server. ... > In any real firewall situation you need two interfaces, ...
      (microsoft.public.windows.server.sbs)
    • Re: Multiple external interfaces
      ... > through extA. ... > All other dual line setups to a single ISP I've seen required static ... proper access/behavior to and from the internet. ... I can register up to 8 interfaces to be connected to the cable modem, ...
      (comp.os.linux.networking)
    • Re: Edge network and internet connection
      ... My machine only have 1 NIC, can it connected to internet? ... connect it to internet via dsl modem or router? ... Make sure that the IP addresses on both interfaces are separate subnets. ...
      (microsoft.public.isa)
    • Re: private network
      ... > port from each machine is hooked up to the internet. ... configure IP addresses on each interface using a subnet defined in RFC ... Or you can use a switch to connect those interfaces to. ...
      (Fedora)