Subject: RE: Enhancing my firewall/gateway: Adding a DMZ
To: tech-net \(E-mail\) <tech-net@netbsd.org>
From: Carleton, Sam \(SCI TW\) <Sam_Carleton_TW@stercomm.com>
List: tech-net
Date: 12/20/2002 13:36:47
-:> > In my current firewall, I have not mucked with any routing to allow
the
-:> > clients to access the Internet.  I have only had to setup IPNat
-:> > correctly. Will this change?  Am I going to have to mess with the
-:> > routing at all for the clients to access the Internet?  My guess is:
no.
-:> > Considering the DMZ is also going to need to be NATed, I assume that
the
-:> > same applies.  Correct? Routing:  I assume that I will have to setup
-:> > some routing for the traffic to go from the Intranet to the DMZ.  How
do
-:> > I go about doing that from both the command line and auto-magically
when
-:> > the firewall reboots. Does anyone have any advice on how to setup the
-:> > ipfilter rules going to the DMZ?
-:> 
-:> No, you only have to set up routing on the additional firewall.

There is no additional firewall, I am simply adding a third NIC to my
current firewall.  

1st NIC --> Internet
2nd NIC --> Intranet
3rd NIC --> DMZ

Will I need to add any routing steps to get from the Intranet to the DMZ?

Sam