Re: Question on rules assosciations, natting.

This is a discussion on Re: Question on rules assosciations, natting. within the IPFilter forums, part of the System Security and Security Related category; [ Charset ISO-8859-1 unsupported, converting... ] > I've got a solaris box acting as a gateway here (finally got ...


Go Back   Usenet Forums > System Security and Security Related > IPFilter

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 07-18-2005
Darren Reed
 
Posts: n/a
Default Re: Question on rules assosciations, natting.

[ Charset ISO-8859-1 unsupported, converting... ]
> I've got a solaris box acting as a gateway here (finally got it up).
>
> When firewalling the box off, can i treat each interface as it's own, or
> will I need to do something special for the setup due to me also natting
> with this.
>
> I've got
> le0 => internet
> le1 => lan
> le2 => Wireless AP (currently left down)
>
> Ideally, le2 is trusted, it's all open, le2, is locked down to vpn
> tunnel port (you login to a vpn run from the gateway which will then
> tunnel all your connections to the net. and le1 faces the internet, can
> I just write rules for each interface, and be done with it? or do I need
> to specially craft rules coming from my internal lan to the internet
> (and back) or will NAT intelligently handle this? Or is this
> accomplished from the keep state?


If you want to force connections to only use (le0,le2) and prevent
(le2,le1), then you can do something like this with keep state:

pass in on le2 out-via le0 proto tcp all flags S keep state

Darren
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 06:40 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0