[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [FW1] Web server in DMZ
Ivan, Did you remember the arp and the route? Shouldn't you be nating to the internal IP? You also need a rule to translate the private ip address source going out bound: src:10.1.1.100 dest: any service:http src:public ip dest: same Also make sure you test from outside the fw. HTH, Pete Goodridge --- Ivan More <[email protected]> wrote: > > Hi, > > We are trying to setup a web server in the DMZ for > public access. But we are not successful. > > Internet > ******** > | > | > | > | > | > ----------- > | | > | | ----- DMZ > | FW |-----------| | web server > | | ----- internal IP 10.1.1.100 > | | external IP > ------------ > | > | > ****** > Office > > > In our rule base we have > > source destination service > Any Web server http > NAT to > external IP > > We did not see any traffic connecting to this web > server even when we try to connect to it (not using > VPN). What did I missed out? > > > Any help will be appreciated. Thanks. > > > Cheers, > Ivan > > _______________________________________________________ > Do You Yahoo!? > Get your free @yahoo.ca address at > http://mail.yahoo.ca > > > ================================================================================ > To unsubscribe from this mailing list, please > see the instructions at > > http://www.checkpoint.com/services/mailing.html > ================================================================================ > __________________________________________________ Do You Yahoo!? Get personalized email addresses from Yahoo! Mail - only $35 a year! http://personal.mail.yahoo.com/ ================================================================================ To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================================================
|