How do I pass WWW (80) through the firewall on two NICs ?

From: Robert Chalmers (robert_at_the-mission-of-our-lady-of-fatima.org)
Date: 12/24/03

  • Next message: hugle: "Re: address specified as 1.2.3.4/24{128,35-55,89} Is this Correct ????"
    To: <freebsd-security@freebsd.org>
    Date: Wed, 24 Dec 2003 16:10:44 +1000
    
    

    I'm getting lost ...

    Running two NICs - no problem. But trying to screw down the rules a bit and getting lost on passing the www - or port 80, through the firewall both waqys.

    There are WebServers - real and virtual, on the inside interface, with their own PublicIP. I'm not using the OutsideInterface as their web address, as I'm using my own DNS etc.

    So, in rc.firewall, what do I put in place so that everything can see my webserver on the inside interface, and also, the workstations on the inside network can see the internet...

    This works fine:

            # Allow access to our WWW
            ${fwcmd} add pass tcp from any to any 80 setup

    However, at the end of rc.firewall, I have to have this in place or I can't get access to the outside world...

            ${fwcmd} add 65000 pass all from any to any
            ;;

    I'm getting lost in the trees, and can't see the forest now.

    Any help appreciated?
    thanks
    Robert

    ---
    The Mission of Our Lady of Fatima.
    http://www.the-mission-of-our-lady-of-fatima.org
    "I come from Heaven. I am the Lady of The Rosary"
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    

  • Next message: hugle: "Re: address specified as 1.2.3.4/24{128,35-55,89} Is this Correct ????"

    Relevant Pages

    • Re: Benefits (and risks) of using Sid
      ... Potato, when I tried to use it, I would get completely lost. ... ncurses interface of aptitude. ... current interface for finding packages in aptitude was designed ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
      (Debian-User)
    • Re: Benefits (and risks) of using Sid
      ... Potato, when I tried to use it, I would get completely lost. ... ncurses interface of aptitude. ... current interface for finding packages in aptitude was designed ... it I'll take a look at how the terminal interface should be updated. ...
      (Debian-User)
    • I have seen this before, please let me know.
      ... I know there is a way to use Scheme as an interface to run ... programs on Matlab and on Scilab, but I lost the URL of some examples on ...
      (comp.lang.scheme)
    • Re: Benefits (and risks) of using Sid
      ... I have NEVER used aptitude ncurses. ... Potato, when I tried to use it, I would get completely lost. ... as I am that interface just does not work the ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
      (Debian-User)