News
:
This forum is now permanently frozen.
m0n0wall Forum
>
m0n0wall Support (English)
>
Firewall/NAT
Topic: DMZ with reverse proxy
Pages: [
1
]
Topic: DMZ with reverse proxy (Read 2178 times)
DMZ with reverse proxy
« on: January 07, 2008, 15:01:32 »
korl
Posts: 2
hello
i'm currently trying to set up a new mail system, but i'm having problems with monowall
the setup is as follows
monowall with 3 interfaces, mailserver on the LAN, reverse proxy that handles incoming mail requests on the DMZ interface, and a static ip address on the wan interface.
now whenever a request comes from wan, it should be portforwarded to the reverse proxy (DMZ) which gets the requested data from Exchange (LAN)
my problem is that i'm unable to communicate from DMZ to LAN (obviously, but i have to open a small hole in the concept to get my system working). so every communication is prohibited, exepting port 443 from DMZ to LAN
i inserted a firewall rule on the DMZ interface, which allows ALL traffic (just for test purposes) from DMZ to LAN
when i try now to ping from DMZ to LAN, i get no response (same for http requests)
how could this be possible?
when i open up the firewall log, it shows me that the packet has been PASSED, but i get no log entry on the Exchange server (LAN)
(http://img410.imageshack.us/img410/9393/zuigus6.jpg)
i'm using monowall 1.3b7 on a warp platform
ps: would you suggest to move exchange to the DMZ ?
Re: DMZ with reverse proxy
« Reply #1 on: January 10, 2008, 05:13:43 »
chain
Posts: 2
The issues is that you need to have your email server sitting in a LAN, the port security of a firewall is that the lan interface is the most secure, you dmz is the port that is secure this enables you to add email server, ftp etc...
LAN >> DMZ allow ping
DMZ >> SMTP Port 25 for email server
DMZ deny all traffic to mail server
Re: DMZ with reverse proxy
« Reply #2 on: January 15, 2008, 11:47:30 »
korl
Posts: 2
even if i was unable to understand what you wanted to tell me, i figured out that the mail server was still using an old gateway, so packets were forwarded, arrived but the responses did never reach the client.
SSDD
Pages: [
1
]