RE: [leaf-user] Public IPs in DMZ with Proxy Arp

2004-02-24 Thread Robert K Coffman Jr - Info From Data Corporation
Ray - thanks again. Forgive me if I was unclear. I've got 5 Bering firewalls in production but this one is bringing a lot of new concepts my way. >This doesn't deal with my uncertainty about the old setup. Was the old >router able to handle the address "xxx.xxx.xxx.142" or not? Yes. >That is,

RE: [leaf-user] Public IPs in DMZ with Proxy Arp

2004-02-23 Thread Ray Olszewski
At 02:37 PM 2/23/2004 -0500, Robert K Coffman Jr - Info From Data Corporation wrote: Ray, Thanks for the response. Answers/comments inline: >Offhand, I cannot think of a way to do what you want to do. Control of >gateway addresses is a function of the routing table, not of ipchains or >iptables

RE: [leaf-user] Public IPs in DMZ with Proxy Arp

2004-02-23 Thread Robert K Coffman Jr - Info From Data Corporation
Ray, Thanks for the response. Answers/comments inline: >Offhand, I cannot think of a way to do what you want to do. Control of >gateway addresses is a function of the routing table, not of ipchains or >iptables. But perhaps I'm missing something. It might help if you clarified >a couple of thin

RE: [leaf-user] Public IPs in DMZ with Proxy Arp

2004-02-23 Thread Ray Olszewski
At 10:55 AM 2/23/2004 -0500, Robert K Coffman Jr - Info From Data Corporation wrote: Tom, Thanks for your assistance. It is much appreciated. > > Question 3: There is a public IP address that has a different gateway than > the block of IP addresses currently in the DMZ. If I use SNAT with tha

RE: [leaf-user] Public IPs in DMZ with Proxy Arp

2004-02-23 Thread Robert K Coffman Jr - Info From Data Corporation
Tom, Thanks for your assistance. It is much appreciated. > > Question 3: There is a public IP address that has a different gateway than > the block of IP addresses currently in the DMZ. If I use SNAT with that > IP, is there any way to specify a different gateway? I'm struggling to > understa

Re: [leaf-user] Public IPs in DMZ with Proxy Arp

2004-02-22 Thread Tom Eastep
On Sunday 22 February 2004 09:15 am, Robert K Coffman Jr - Info From Data Corporation wrote: > I've been pouring through the docs and archives but can't seem to find the > answer to these. > > I've got a setup similar to Tom's 3 interface example, but with public IPs > in the DMZ and proxy arp set

RE: [leaf-user] Public IPs in DMZ with Proxy Arp

2004-02-22 Thread Robert K Coffman Jr - Info From Data Corporation
I've been pouring through the docs and archives but can't seem to find the answer to these. I've got a setup similar to Tom's 3 interface example, but with public IPs in the DMZ and proxy arp set to allow access to them. Question 1: If I want to firewall all but the necessary public services fro