[ previous ] [ next ] [ threads ]
 From:  "Rodman Frowert" <frowertr at i dash 1 dot net>
 Cc:  <m0n0wall at lists dot m0n0 dot ch>
 Subject:  Re: [m0n0wall] Unable to ping DMZ hosts from LAN
 Date:  Wed, 8 Sep 2004 08:59:17 -0500
Actually, it makes perfect sesnse.  I just can't get it wor work.  Here is 
what I have setup:

Static route:
      Interface Network Gateway Description

Remember, my Lan is on with the m0n0 LAN interface on
My DMZ is on with the DMZ interface on

I put a rule at the top of my DMZ that says:

      Proto Source Port Destination Port      Description
      * LAN Net   * DMZ *      *

This should allow any traffic into the DMZ from the LAN, correct?

Here is what I get when I try to ping (my switch) from my LAN:

Pinging with 32 bytes of data:

Reply from TTL expired in transit.
Reply from TTL expired in transit.
Reply from TTL expired in transit.
Reply from TTL expired in transit.

Ping statistics for
    Packets: Sent = 4, Received = 4, Lost = 0 (
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms

If I do a Tracert command for from my LAN this is what I get:
Tracing route to over a maximum of 30 hops
  1    <1 ms    <1 ms    <1 ms  firewall.local []
  2    <1 ms    <1 ms    <1 ms  firewall.local []
  3    <1 ms    <1 ms    <1 ms  firewall.local []
  4    <1 ms    <1 ms    <1 ms  firewall.local []
  5    <1 ms    <1 ms    <1 ms  firewall.local []
  6    <1 ms    <1 ms    <1 ms  firewall.local []
  7    <1 ms    <1 ms    <1 ms  firewall.local []
  8    <1 ms    <1 ms    <1 ms  firewall.local []

It will go to 30 and them finally time out.  It is almost like the doesn't know what to do with this packet it is getting with a 
destination of

I do apreciate the help guys.  It is just frustrating that this isn't 
working properly...


>Interface Network           Gateway
>ok that what my static route looks like. What that is saying is that any
>traffic from my 192.168.20.x/24 network to the destination network of
>192.168.10.x/24, use the gateway of (the wifi card)
>does that help?
>Chet Harvey