Subject: RE: Enhancing my firewall/gateway: Adding a DMZ
To: tech-net \(E-mail\) <tech-net@netbsd.org>
From: Carleton, Sam \(SCI TW\) <Sam_Carleton_TW@stercomm.com>
List: tech-net
Date: 12/20/2002 13:36:47
-:> > In my current firewall, I have not mucked with any routing to allow
the
-:> > clients to access the Internet. I have only had to setup IPNat
-:> > correctly. Will this change? Am I going to have to mess with the
-:> > routing at all for the clients to access the Internet? My guess is:
no.
-:> > Considering the DMZ is also going to need to be NATed, I assume that
the
-:> > same applies. Correct? Routing: I assume that I will have to setup
-:> > some routing for the traffic to go from the Intranet to the DMZ. How
do
-:> > I go about doing that from both the command line and auto-magically
when
-:> > the firewall reboots. Does anyone have any advice on how to setup the
-:> > ipfilter rules going to the DMZ?
-:>
-:> No, you only have to set up routing on the additional firewall.
There is no additional firewall, I am simply adding a third NIC to my
current firewall.
1st NIC --> Internet
2nd NIC --> Intranet
3rd NIC --> DMZ
Will I need to add any routing steps to get from the Intranet to the DMZ?
Sam