Re: [leaf-user] Types of DMZ - Dachstein

2003-10-13 Thread Charles Steinkuehler
Doug Sampson wrote: I'm using Dachstein CD 1.02 which works well in its present state. I would like to add a DMZ using a second ethernet card. I see in the network.conf file there are various types of DMZ- YES, PROXY, NAT, PRIVATE, and NO. I do not know what a PROXY DMZ does nor do I know the purpo

RE: [leaf-user] Types of DMZ - Dachstein

2003-10-13 Thread Doug Sampson
> DMZ=PROXY > This setting uses proxy-arp to separate your DMZ systems from the "raw" > upstream connection. The main benefit to using proxy-arp is your DMZ > systems can have REAL PUBLIC IP's. The main drawback is it's kind of > complex to get the networking and firewall rules setup correctly

Re: [leaf-user] Types of DMZ - Dachstein

2003-10-14 Thread Charles Steinkuehler
Doug Sampson wrote: Very useful information, Charles. Although I don't quite get what proxy-arp really does and how it differs from, say, a strictly public DMZ. Perhaps a short explanation here will help set my mind straight. I am confused especially by the statement regarding separating the DMZ sy