Re: ipfw ?? DNAT ?? Help

From: Wil (wil@REMOVE.wilcomm.net)
Date: 06/21/02


From: "Wil" <wil@REMOVE.wilcomm.net>
Date: Fri, 21 Jun 2002 07:11:53 -0700

Not to sure about picoBSD, however on a PIX you have to 'doctor' the DNS
entery by setting up an alias entry.
i.e.
The PIX will see a DNS lookup for http://myname.dyndns.org 's public IP
address and change the reply to 192.168.x.x....
So when you nslookup http://myname.dyndns.org from the inside you should get
a 192.168.x.x response.

--
Wil
my 2¢
"When everything seems to be going well, you have obviously overlooked
something."

"Thierry" <lenaig@wanadoo.fr> wrote in message news:aet8q8$pl0$1@wanadoo.fr... > Hi all, > > I have a picoBSD firewall. My web server is on a dmz. > > The name of my web server is myname.dyndns.org or 192.168.x.x.... > > I can browse my web server from the lan (http://192.168.x.x), outside people > can do the same thing, but me, i can't do it from my lan, if i do, from my > lan computer http://myname.dyndns.org it is not working. > > lan <--> web (dmz) OK > > www <--> web (dmz) OK > > lan <--> by dyndns <--> web (dmz) NO OK > > I get the same problem when i was using iptables (linux) and i resolve it > with a DNAT rules (prerouting) . > > I don't know the ipfw rules to much, and i am looking to find solution > similar to the iptables. > > Thanks a lot. > > Thierry > > >



Relevant Pages

  • File sharing problems across PIX 502 firewalls
    ... I have a LAN segment that connects to the Internet through ... a PIX 501 firewall, fairly typical settings using a Pooled NAT ... I can see the web server fileshares via their UNC ...
    (comp.security.firewalls)
  • Re: ipfw ?? DNAT ?? Help
    ... however on a PIX you have to 'doctor' the DNS ... My web server is on a dmz. ... > can do the same thing, but me, i can't do it from my lan, if i do, from my ...
    (comp.security.firewalls)
  • Re: Back-to-Back Firewall Pix & ISA Server 2004
    ... DNS will mean nothing for your ISA. ... your Internal DNS that the LAN machines use. ... The PIX must allow the AD/DNS to make outbound DNS Queries ...
    (microsoft.public.isa.configuration)
  • Re: DDoS or not? More lies or Incompetence?
    ... >Their FTP server was accessible. ... >builds a LAN that fails if their web server fails? ... with the LAN side if the topology is too centralized. ... DNS server reside on the same machine. ...
    (comp.unix.sco.misc)
  • Comcast DNS Routing Problem?
    ... The router is configured to pickup the IP and DNS addresses from ... act as a DHCP within my LAN, and I manually assigned static IP addresses to ... bypass the firewall for my web server, whose static IP is configured as the ...
    (comp.security.firewalls)