Re: NAT between OPT1 and LAN

Terry Yim <[email protected]>
Newsgroups gmane.comp.security.firewalls.m0n0wall
Message-ID <[email protected]>
David,

Thank you for your suggestion.

The idea of doing the NAT is to prevent the user in OPT1 to see/know the LAN's IP subnet through the printer IPs.  I was trying to tie down the security.

Luckily, the printers have the option to put in a default GW, which is the m0n0wall LAN interface 10.31.0.10.

I shall try taking out the NAT rules and see how m0n0wall behaves.

-Terry

--- On Thu, 11/11/10, David Burgess <[email protected]> wrote:

> From: David Burgess <[email protected]>
> Subject: Re: [m0n0wall] NAT between OPT1 and LAN
> To: 
> Cc: [email protected]
> Date: Thursday, November 11, 2010, 7:36 PM
> On Thu, Nov 11, 2010 at 12:48 PM,
> Terry Yim <[email protected]>
> wrote:
> 
> > I have a user on OPT1 (10.79.0.10) that needs to
> access 3 printers inside the LAN (10.31.0.40-10.31.0.42).
>  I have created 3 NAT rule on the OPT1 interface
> (10.79.0.40 -> 10.31.0.40 and so on) with proxy ARP on
> all those IPs.
> 
> 
> If the printers are or can be configured with a default
> route (which
> they would get from dhcp if they're using it), then there
> is no need
> to set up a single NAT rule for this. Save yourself the
> trouble.
> 
> If the network printers won't take a default gateway then
> you need new printers.
> 
> db
> 
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]
> 
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.