From owner-freebsd-security@FreeBSD.ORG Tue Dec 23 22:10:49 2003 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 9787F16A4CE for ; Tue, 23 Dec 2003 22:10:49 -0800 (PST) Received: from nanguo.chalmers.com.au (220-244-9-90-qld.tpgi.com.au [220.244.9.90]) by mx1.FreeBSD.org (Postfix) with ESMTP id B54F043D39 for ; Tue, 23 Dec 2003 22:10:46 -0800 (PST) (envelope-from robert@chalmers.com.au) Received: from carbon (carbon.chalmers.com.au [203.1.96.26]) hBO6AjxW000390 for ; Wed, 24 Dec 2003 16:10:45 +1000 (EST) Message-ID: <007501c3c9e4$ab16caf0$1a6001cb@chalmers.com.au> From: "Robert Chalmers" To: Date: Wed, 24 Dec 2003 16:10:44 +1000 Organization: The Mission of Our Lady of Fatima MIME-Version: 1.0 X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2800.1158 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable X-Content-Filtered-By: Mailman/MimeDel 2.1.1 Subject: How do I pass WWW (80) through the firewall on two NICs ? X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: Robert Chalmers List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 24 Dec 2003 06:10:49 -0000 I'm getting lost ... Running two NICs - no problem. But trying to screw down the rules a bit = and getting lost on passing the www - or port 80, through the firewall = both waqys. There are WebServers - real and virtual, on the inside interface, with = their own PublicIP. I'm not using the OutsideInterface as their web = address, as I'm using my own DNS etc. So, in rc.firewall, what do I put in place so that everything can see my = webserver on the inside interface, and also, the workstations on the = inside network can see the internet... This works fine: # Allow access to our WWW ${fwcmd} add pass tcp from any to any 80 setup However, at the end of rc.firewall, I have to have this in place or I = can't get access to the outside world... ${fwcmd} add 65000 pass all from any to any ;; I'm getting lost in the trees, and can't see the forest now. Any help appreciated? thanks Robert --- The Mission of Our Lady of Fatima. http://www.the-mission-of-our-lady-of-fatima.org "I come from Heaven. I am the Lady of The Rosary"