Re: local DNAT with bind,postfix,and iptables

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



> ----- Original Message -----
> From: "Gaby Schilders"
>
> Perhaps I'm out of line here,

No. Not at all :)

but there are several ways leading to Rome,
> as
> they say here.
>
> 1) Postfix trick mentioned by George (and obviously having only one
> postfix
> box instead of two with a voodoo like setup to compensate... ;-)
> 2) Bind views (show the internal world something different than the
> outside). This seems to generally be the most standard and most advised
> way
> of handling this kind of problem. See the Bind administrator guide at
> isc.org.
> 3) Local DNAT has been implemented but through p-o-m patches (in
> CVS/snapshots only afaik), not standard kernel and I've never tried it so
> I
> don't know how good it will work. Use the CVS web-interface to look at the
> patches/comments.

Those insights are really useful.  Upon reading what you've mentioned, I
remember split DNS.  The postfix trick by George was also new to me.
However, I don't think I could try the patch soon.


> 4) There was a four. It slipped my mind while thinking of the other
> options
> and I'll mention it as soon as it comes back to me... :-|
>
> If you need more explanation, do ask, but I'm very busy today/tomorrow so
> I
> may not respond before Monday.

Ok.  Just make sure you post them.  It could be something new and something
I haven't heard of before.
Some might also find that useful.

Thanks!

Best Regards,

Carlo
------
Carlo Florendo
Astra Philippines Inc.
www.astra.ph



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux