[KLUG Members] NAT, firewalls, BSD/Linux

Peter Buxton members@kalamazoolinux.org
Sat, 13 Oct 2001 05:22:33 -0400


> > Why wouldn't you be using NAT?
>
> I'm building a firewall for the office here, which has a few servers with
> live internet IPs, which need to have direct access: web servers, etc.
>
> Anyway, I'm following a doc here for a bridging firewall, and I think this
> is what I need...  
>
> I guess it needs to be a bridge, to act as a go-between for the IPS that
> lie behind it.

Not necessarily, just use Proxy ARP so outside hosts may find your IP #'s:

http://www.sjdjweis.com/linux/proxyarp/

or:

http://www.linuxdoc.org/HOWTO/mini/Proxy-ARP-Subnet/index.html

The first sounds more like what you need. Address Resolution Protocol is
itself a routing solution, which is what you seem to need.

-p

-- 
Rebuild the Towers!
http://www.angelfire.com/linux/somercet