News: This forum is now permanently frozen.
Pages: [1]
Topic: DMZ with reverse proxy  (Read 2178 times)
« on: January 07, 2008, 15:01:32 »
korl *
Posts: 2

hello
i'm currently trying to set up a new mail system, but i'm having problems with monowall
the setup is as follows

monowall with 3 interfaces, mailserver on the LAN, reverse proxy that handles incoming mail requests on the DMZ interface, and a static ip address on the wan interface.
now whenever a request comes from wan, it should be portforwarded to the reverse proxy (DMZ) which gets the requested data from Exchange (LAN)
my problem is that i'm unable to communicate from DMZ to LAN (obviously, but i have to open a small hole in the concept to get my system working). so every communication is prohibited, exepting port 443 from DMZ to LAN

i inserted a firewall rule on the DMZ interface, which allows ALL traffic (just for test purposes) from DMZ to LAN
when i try now to ping from DMZ to LAN, i get no response (same for http requests)

how could this be possible?
when i open up the firewall log, it shows me that the packet has been PASSED, but i get no log entry on the Exchange server (LAN)

(http://img410.imageshack.us/img410/9393/zuigus6.jpg)

i'm using monowall  1.3b7 on a warp platform
ps: would you suggest to move exchange to the DMZ ?
« Reply #1 on: January 10, 2008, 05:13:43 »
chain *
Posts: 2

The issues is that you need to have your email server sitting in a LAN, the port security of a firewall is that the lan interface is the most secure, you dmz is the port that is secure this enables you to add email server, ftp etc...

LAN >> DMZ allow ping
DMZ >> SMTP Port 25 for email server
DMZ deny all traffic to mail server
« Reply #2 on: January 15, 2008, 11:47:30 »
korl *
Posts: 2

even if i was unable to understand what you wanted to tell me, i figured out that the mail server was still using an old gateway, so packets were forwarded, arrived but the responses did never reach the client.
SSDD  Grin
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines