fp and dmz

fp and dmz

Post by Max M. Stalnake » Tue, 07 Jan 2003 03:47:49

I have a openbsd 3.2 pf firewall with three nic cards.  One is external,
one is a protected network, and one is a dmz.  The external and
protected seem to be set up to my wishes.  A web server in the dmz is
nicely accessible from the internet.  It has a seperate static ip on the
external interface, the web server has a non-routable address, and I nat
its address and do a redirect for port 80 and it works.  I got this far
by cut and try.

Suppose I now want to isolate the web server on the dmz further.  I try
various pass in and pass outs on the dmz interface and just get in
trouble.  The faq hints that trying this sort of combination of nat,
rdr, pass, and block, requires specialized knowledge, which it is now
obvious I do not have.

This is intended to be a prototype for a four nic card firewall on which
  the new nic card runs a wi-fi ap.  At this point, my failure to
control the dms interface completely suggest the wi-fi ap will need a
seperate firewall and if I really want to control the dmz further, I
would need a firewall box for it.

Is there an alternative I can implement with just one firewall box or is
my proposed approach of multiple firewall boxes the best approach for me?


1. How to remove Apache/FP 1.2.5 and FP 3.0 extensions

After a misguided attempt to add the Apache 1.2.5 (FrontPage) "patch"
Appache 1.2.6 (on RedHat Linux 5.1), my FP 3.0 extensions are now
hopelessly broken.  How may I remove both packages ?  I tried "rpm -e
apache" but it returns some error about dependencies.  "fpsvradm -o
uninstall -p 80 -m ..." does appear to work for the virtual webs, but I
reallyt would like to clean out FP extensions everywhere (roots. subwebs,
virtuals, etc.)


Ken Onwere
PS.  The webserver does appear to be running great, though.

2. Per user: Restricting Telnet but allowing FTP

3. Matrox Mystique ands X.

4. problems with installation of 2 apache server

5. FP extensions on apache wwwserver

6. How to write an AIX SCSI driver?

7. HIPPI PCI card FP driver needed

8. CD-I


10. xset +fp /tcp/<hp-ux_server_name>:7000 hangs on Solaris 10

11. IEEE FP and Linux

12. Apache FP extensions problem

13. How do I add php4 with apache-fp