News: This forum is now permanently frozen.
Pages: [1]
Topic: Very confused with NAT  (Read 2635 times)
« on: May 30, 2007, 19:09:31 »
kpeterson *
Posts: 3

I am setting up m0n0wall as a replacement for out 3com superstack firewall and I am having lots of trouble under standing the nat and  firewall rules. I know anything comming from the WAN would need a nat rule + a firewall rule. What if I want to allow https from the dmz to lan? Do I need a nat rule for that? Here are some details..

lan - 192.168.10.1
dmz - 192.168.101.1
wan - 207.xxx.xxx.xxx

I need to allow https from 192.168.101.11 to a range of ips 192.168.10.30 to 192.168.10.35.

How would I do this? Please help, the more I think about it the more confused I get. Thanks
« Reply #1 on: May 30, 2007, 20:33:27 »
clarknova ***
Posts: 148

You don't need a NAT rule. You need to create a firewall rule thus:

Action: Pass
Interface: LAN
Protocol: TCP
Source: Network/ Single host or alias (you will need to create a rule for each of 10.30 through 10.35, or a couple rules with subnets to cover these same addresses)
Destination: 101.11
Destination port range: https

That should do it.

db
« Reply #2 on: May 31, 2007, 10:35:33 »
bitonw **
Posts: 79

in a point of security. why do you want to allow traffic from a DMZ to LAN...  Huh
« Reply #3 on: May 31, 2007, 17:30:32 »
clarknova ***
Posts: 148

in a point of security. why do you want to allow traffic from a DMZ to LAN...  Huh

Although kpeterson did say that, I made the perhaps erroneous assumption that he or she meant that the https server is on the DMZ (101.11) while the clients that need access are on the LAN (10.30 - 1-.35). This is the scenario I drew up a rule for in my previous post, however I could be wrong in my assumption.

db
« Reply #4 on: June 04, 2007, 21:46:47 »
kpeterson *
Posts: 3

I got it all figured out, Thanks for the help. I just havent encounter a firewall that had nat rules and firewall rules I was a little confused. Now I am having trouble when I connect m0n0wall to my lan, dmz and wan work but I get no link on the lan. No idea whats going on.
« Reply #5 on: June 05, 2007, 06:20:01 »
clarknova ***
Posts: 148

You should start a new thread for this.

db
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines