Re: question

From: Lars M. Hansen (badnews_at_hansenonline.net)
Date: 07/10/04


Date: Sat, 10 Jul 2004 17:30:04 -0400

On Wed, 7 Jul 2004 14:15:22 +0000 (UTC), Ognen Duzlevski spoketh

>Hi,
>
>we have several boxes with unique public IP addresses which are part of a big .edu namespace. I would like to put these
>machines behind one single firewall and still keep their names. Is it possible to have all names point to the firewall
>machine and then have the firewall direct the specific request to a specific box behind it?
>
>So, if F is firewall.x.edu and I have A.x.edu, B.x.edu and C.x.edu I want to have A, B and C behind F. A, B and C
>should now point to F and F will direct all outside requests to A, B or C based on the name.
>
>Thanks,
>Ognen

You can get firewalls that'll allow you to map external IP addresses to
internal (either LAN or DMZ) IP addresses. This will allow you to place
these machines behind the firewall without having to worry about
changing DNS records for these computers.

However, a firewall can not redirect based on names, so you cannot point
the DNS records for all these machines to the firewall and have the
firewall forward based on the DNS name.

Lars M. Hansen
http://www.hansenonline.net
(replace 'badnews' with 'news' in e-mail address)