[ previous ] [ next ] [ threads ]
 
 From:  Mark Wass <mark dot wass at market dash analyst dot com>
 To:  Steve Yates <steve at teamITS dot com>
 Cc:  m0n0wall at lists dot m0n0 dot ch
 Subject:  Re: [m0n0wall] Rules to Servers on Opt1
 Date:  Fri, 30 Sep 2005 11:01:13 +1000
Hi Steve

This is my setup.

    Internet
       |
       |
       | IP = X.Y.Z.13/30 This is a plublic IP
   MonoWall
     |   | Opt1 Int IP = A.B.C.1/27 This is a plublic IP
     |   |
     |   |
     |   --------> Web Server IP = A.B.C.2/27 This is a plublic IP
     |  
LAN Subnet

The A.B.C.0/27 Network is routed to my MonoWall box (X.Y.Z.13/30)

All I want to know is what rule do I need to apply to the WAN interface 
to allow access to a web server with a PUBLIC IP on the Opt1 interface.

Also I want to make sure hosts on the LAN subnet can access the Web 
server on the OPT1 subnet, so any rules that may be needed for that 
would be helpful also.

I am NOT doing any NAT on the OPT1 interface (Unless someone states I 
have to, but I would think I don't have to)

This is the rule I was going to use to allow access from the Internet to 
the Web server

Rule on the WAN interface.

Pass/Block   Proto    Source   Port   Destination   Port
  
  Pass        *        *       *      A.B.C.2       80

Can someone please confirm this is correct?

I'm sorry if this seems like a stupid question, I'm just trying to make 
sure I understand how these rules work.

Steve Yates wrote:

>On Fri, 30 Sep 2005 09:30:35 +1000
>Mark Wass <mark dot wass at market dash analyst dot com> wrote:
>
>  
>
>>I did not plan to, did I have to?
>>    
>>
>
>	I was hoping someone else would jump in, but it sounded to me
>like you were setting up firewall rules to permit or disallow traffic. 
>However wouldn't you also need to route the traffic between WAN and OPT1
>somehow?  Like with a static route?
>
>  
>
>>>>If I have a web server on Opt1 that has a REAL IP of A.B.C.2/27 is this 
>>>>the correct rule to allow access to it from the WAN interface.
>>>>        
>>>>
>
> - Steve Yates
> - ITS, Inc.
> - Wisdom of Bart: I am not authorized to fire substitute teachers
>
>~ Taglines by Taglinator 4 - www.srtware.com ~
>
>
>  
>