On 5 Apr 2000, Ash R. J. Wyllie wrote:

> I'd like to follow up on the last, Fred. My DNSs are known, 208.xxx.yyy.zzz
> and something else I can't even remember the first number of. I assume that
> htey are by definition static? So could I arrange to have Miami's firewall to
> pass only packets from the DNSs to ports 48000/65535?

Yes.  They're "static", but they could still change from time to time, and
you'd need to track that.

> A look at the firewall settings suggests that one could also set up the 
> firewall to allow outside access to say port 5000 of the machine with IP
> number 192.168.1.5, and only that port on that machine. Sending a packet to
> port 5000 of 192.168.1.6 or 192.168.1.4 would not be permitted.

I believe the firewall comes before the NAT processing, which means that
this wouldn't work because the packets seen by the firewall aren't using
the private IP addresses.  In most cases, the D-IP in the firewall is
only useful when you don't use NAT.

                                        Fred Wright

-- 

To unsubscribe send "unsubscribe miami-talk-ml" to
"[EMAIL PROTECTED]". For help on list commands send "help" to
"[EMAIL PROTECTED]".


Reply via email to