![](https://seccdn.libravatar.org/avatar/525429879e31958a513b2106164c44af.jpg?s=120&d=mm&r=g)
Jim Staunton wrote:
I have several SuSE 10.3 systems which have one network card but multiple ip addresses, the additional addresses are set up as aliases through YaST. For instance on one system, eth0 is x.y.z.69, eth0:1 is x.y.z.70 and eth0:2 is x.y.z.71.
Is there any way I can allow access to specific ports/services on specific ip addresses through YaST's SuSEfirewall2 module? I'm aware that I could do this 'manually' using iptables, but I'd prefer to do it the 'SuSE way' using YaST or entries in /etc/sysconfig/SuSEfirewall2 - always assuming there is a SuSE way to do this :-)
I'm thinking of rules such as "allow ssh access to the box only on x.y.z.69", "allow a webserver to be accessed on x.y.z.70", "allow a mailserver to be accessed on "x.y.z.71".
Any ideas welcome....
Thanks,
Jim Hi Jim,
Open Yast>Security and Users>Firewall>Use the custom rules tab. This is a new addition to the firewall only from versions 10.3 upwards. I really dont understand why your routing tables are so complex. O.K out of you Router use NAT (Network Address Translation) and turn on DHCP. If your router has only 1 LAN Port then you will need a switch to provide multiple cables to each PC. If your router has multiple LAN ports use 1 for each PC. You do NOT have to use an OpenSuse PC to hand out IP's, Let the router simply do it via NAT and DHCP. Configure each Network card with only 1 IP and you can use DHCP+Zero config to ensure that only DHCP has handed an IP to each PC via DHCP, you can rest assured that the same IP will always be handed to the same PC by using the DHCP+Zero config. This new feature in 10.3 permits each PC to have a static IP, however in the first instance it was obtained via DHCP. I have no idea why you want to maintain complex routing tables when it is not necessary. Let you router assign private IP's 192.168.1.0/24 via NAT out of the LAN port of your router. You do NOT need a PC to manage complex routing tables and hand out the IP's Scott - Good Luck -- To unsubscribe, e-mail: opensuse+unsubscribe@opensuse.org For additional commands, e-mail: opensuse+help@opensuse.org