23 May
2003
23 May
'03
18:49
Maarten,
Yeah... I wondered about that too... The thing is, If I do not masquerade LAN to my DMZ how do I allow access from LAN to my DMZ servers ? Am I overlooking something ?
Using FW_FORWARD="<lanipnet>/<bitmask>,X.Y.Z.160/28" Though I would expect the lan to have access to dmz, just like it has access to the outside, but when not masquerading, maybe this should be done explicitly. You could do masquerading, but then set masq nets option to internal ip range. Ah well, if that does not seem to work, build your own from the ground up. :) There are tools to make that easy too. Arjen