[ previous ] [ next ] [ threads ]
 
 From:  Chris Buechler <cbuechler at gmail dot com>
 Cc:  m0n0wall at lists dot m0n0 dot ch
 Subject:  Re: [m0n0wall] I have to ask
 Date:  Wed, 7 Sep 2005 21:05:21 -0400
On 9/7/05, Peter <peter at iwebsl dot com> wrote:
> This is potentially a daft question but .... I really need to know ;-)
> 
> It it imperative to physically separate the LAN & DMZ ?
> 

Yes.  m0n0wall tends to not be happy when two interfaces are on the
same broadcast domain (sometimes to the extent that nothing works). 
Regardless, putting them on the same broadcast domain eliminates the
point of having a DMZ in the first place.

-Chris