Other Interfaces
. The DMZ uses subnet
192.168.2.x
, the web server's IP
address is
192.168.2.2
.
Now you will add the following rules:
Make the web server accessible from the Internet — mapping HTTP service on the server in the DMZ,
Allow access from the DMZ to the Internet via NAT (IP address translation) — necessary for correct functionality of
the mapped service,
Allo access from the LAN to the DMZ — this makes the web server accessible to local users,
Disable access from the DMZ to the LAN — protection against network intrusions from the DMZ. This is globally
solved by a default rule blocking any other traffic (here we have added the blocking rule for better understanding).
Screenshot 77: Traffic rules for the DMZ
www.gfi.com
4 Settings
Do'stlaringiz bilan baham: |