Unwound my work stack to carry on with this...had a chance to review the docs again and there's one point I'm not sure about. For clarity, the question was about using a Zyxel modem in Bridge mode, which automatically disables NAT and how to configure shorewall to take over the role.
Tom Eastep wrote: > On 02/25/2013 09:50 AM, Ruth Ivimey-Cook wrote: >> I think I have to add an entry to "masq" like this to enable NAT, where >> the first IP is my internal net block and the second is my main internet IP: >> eth2 192.168.1.0/24 82.62.47.198 >> >> Is that all I need to do to emulate what my modem's NAT is doing now? > Should be. My router has a "default server" in its NAT setup. NATs everything on 192.168.1.0/24 but has a default server set as 192.168.1.2. This is needed because my internal network runs on another IP block - say 192.168.8.0/24 - so that only the "DMZ" zone between the router and the firewall is 192.168.1.0/24. I'm thinking that essentially I loose the 192.168.1.0/24 zone because what is left of it will be firewall-internal, but I'm not sure, and in any case how do I talk to the modem if it's no longer got an IP? So: if I do need both IP zones, is the old default server setting still necessary, and how to I talk to the modem config if it no longer has an IP of its own? Sorry, rather confused as you can see, Ruth -- Software Manager & Engineer Tel: 01223 414180 Blog: http://www.ivimey.org/blog LinkedIn: http://uk.linkedin.com/in/ruthivimeycook/ ------------------------------------------------------------------------------ Everyone hates slow websites. So do we. Make your web apps faster with AppDynamics Download AppDynamics Lite for free today: http://p.sf.net/sfu/appdyn_d2d_feb _______________________________________________ Shorewall-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/shorewall-users
