From owner-freebsd-questions@FreeBSD.ORG Sun Feb 20 02:41:18 2005 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 22F7616A4CE for ; Sun, 20 Feb 2005 02:41:18 +0000 (GMT) Received: from rwcrmhc13.comcast.net (rwcrmhc13.comcast.net [204.127.198.39]) by mx1.FreeBSD.org (Postfix) with ESMTP id EB56443D39 for ; Sun, 20 Feb 2005 02:41:17 +0000 (GMT) (envelope-from fbsd-questions@trini0.org) Received: from hivemind.trini0.org (trini0.org[65.34.205.195]) by comcast.net (rwcrmhc13) with ESMTP id <2005022002411701500kuh0ce>; Sun, 20 Feb 2005 02:41:17 +0000 Received: from [192.168.0.16] (gladiator.trini0.org [192.168.0.16]) by hivemind.trini0.org (Postfix) with ESMTP id 118E16125 for ; Sat, 19 Feb 2005 21:41:17 -0500 (EST) Message-ID: <4217F8CF.5030508@trini0.org> Date: Sat, 19 Feb 2005 21:41:19 -0500 From: Gerard Samuel User-Agent: Mozilla Thunderbird 1.0 (X11/20050122) X-Accept-Language: en-us, en MIME-Version: 1.0 To: freebsd-questions Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Subject: Reconfiguring my network X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 20 Feb 2005 02:41:18 -0000 I currently own my own domain name, and run a dns server that services only the lan (i.e. It just forwards requests to my ISP's dns server, and resolves computers on the lan). Other services, (i.e. www/mail/cvs/etc) are port forwarded through the firewall. The setup is ok, but I have it in my mind, that I can *grow* the setup beyond what it is currently (its been this way for the past 4-5 years, and Im looking to see if it can change). Today, I've been trying to see if it was possible to get the dns server/lan, more accessible to the internet, so that I can do away with port forwarding (maybe not completely). Where other dns servers can query my dns server, so that the lan is more accessible (maybe not the right word), with some voodoo to get around a *real* single ip, and internal virtual ip addresss. Is it even possible with a setup like mine (psuedo diagram below)? If so, can you give a synopsis on what to do, and or any resources on the net that can guide me? Thanks for your time. INTERNET | | FIREWALL (FreeBSD running DNS/DHCP/IPF/IPNAT) | | SWITCH | | LAN (Various servers & workstations)