port forwarding

Nikolay A. Fetisov email hidden
Fri Jul 25 06:25:31 CEST 2008


On Thu, 24 Jul 2008 14:35:51 -0700
Gary Koskenmaki wrote:

> ....
> I set up a webserver in a dmz and it is accessible from the internet ...
>  However, I cannot access that web server from the INT zone...

Do You allow HTTP traffic from INT to DMZ zone?
Default configuration files pass only ssh, see line 

FORWARD[1]="INT ACCEPT tcp ssh 0.0.0.0/0=>0.0.0.0/0"

in zone.dmz.

BTW, FIAIF logs rejected/dropped packets, a lot of useful information
could be found in /var/log/messages .

-- 
Best regards,
Nikolay Fetisov


More information about the fiaif mailing list