Re: iptables firewall and forwarding.

From: Seth Arnold (sarnold@wirex.com)
Date: 10/22/02


Date: Mon, 21 Oct 2002 21:29:11 -0700
From: Seth Arnold <sarnold@wirex.com>
To: focus-linux@securityfocus.com


On Fri, Oct 18, 2002 at 12:07:47PM -0400, Sheldon Lee Wen wrote:
> The dev servers are on network xxx.xxx.xxx.xxx and the developer workstations
> are on yyy.yyy.yyy.yyy

> However, the development servers use to be on the yyy.yyy.yyy.yyy and
> the raptor firewall has been forwarding their old yyy.yyy.yyy.yyy
> addresses to the xxx.xxx.xxx.xxx addresses, but the raptor firewall is
> not the router or gateway for the yyy.yyy.yyy.yyy network. So, I'm not
> sure how I can do that on Linux. Has the raptor firewall been acting
> as a router as well? Do I need routed on Linux?

I _think_ what you've described is done through DNS; do your development
workstations try to access foo.bar.internal.address or do they try to
access 10.2.4.5 or something? If the former, then this is very easy DNS
stuff. If the latter, then you should ask your employees to learn the
new IP addresses of the servers. :)

You may like to google for BIND HOWTO; I think it is probably the
solution to this problem.

Cheers

-- 
http://immunix.org/




Relevant Pages

  • Re: iptables firewall and forwarding.
    ... Assuming developer workstations on 192.168.0.1/24 and servers on ... > servers use to be on the yyy.yyy.yyy.yyy and the raptor firewall has been ... > yyy.yyy.yyy.yyy network. ...
    (Focus-Linux)
  • iptables firewall and forwarding.
    ... now my boss wants to put in a linux firewall. ... The dev servers are on network xxx.xxx.xxx.xxx and the developer workstations ... servers use to be on the yyy.yyy.yyy.yyy and the raptor firewall has been ...
    (Focus-Linux)
  • Re: iptables firewall and forwarding.
    ... > developer workstations to the development servers. ... > servers use to be on the yyy.yyy.yyy.yyy and the raptor firewall has been ... > yyy.yyy.yyy.yyy network. ...
    (Focus-Linux)
  • Re: Dcidag errors
    ... Port blockage between servers ... Other sorts of networking issues (lack of connectivity between the points ... These errors are typically a result of a network connectivity issue of some ... > replicating this nc. ...
    (microsoft.public.windows.server.active_directory)
  • Re: I need Job Blobb
    ... > Windows and Network administratation. ... > In a job I would like to administrate servers, ... > Title: ISP Network Administrator ... > o Building, installation, configuration and tuning ...
    (microsoft.public.cert.exam.mcse)