RE: browsing the "network 'hood" from LAN <-> DMZ

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Duh

And again I say Duh.  What a spanner.

Thanks for that Chris - I am suitably larted.

S




-----Original Message-----
From: Chris Brenton [mailto:cbrenton@xxxxxxxxxxxxxxxx] 
Sent: 5 December 2003 12.34
To: Knight, Steve
Cc: netfilter
Subject: Re: browsing the "network 'hood" from LAN <-> DMZ


On Fri, 2003-12-05 at 07:12, Knight, Steve wrote:
>
> I'm trying to get the LAN to be able to NBT browse the boxes in the DMZ,
but
> they won't.  I'm permitting all TCP and UDP from LAN to DMZ and back again
> ...  It looks like NetBIOS isn't going to and from eth0-eth1.

First off this is a ***BAD*** idea. You've just removed all security a
DMZ can provide and IMHO you are not much better off than if hosted the
servers on your internal network.

Now with all that said, on the internal network edit the lmhosts file
and add an entry for the system(s) on the DMZ. That or you could setup a
WINS server and point all your systems at it.

HTH,
C




.


-----------------------------------------------------------------------
Information in this email may be privileged, confidential and is 
intended exclusively for the addressee.  The views expressed may
not be official policy, but the personal views of the originator.
If you have received it in error, please notify the sender by return
e-mail and delete it from your system.  You should not reproduce, 
distribute, store, retransmit, use or disclose its contents to anyone.
 
Please note we reserve the right to monitor all e-mail
communication through our internal and external networks.
-----------------------------------------------------------------------



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux