First off, I want to say I'm quite impressed with what Astaro has to offer for a network / Internet connection and security solution. Granted, I still have yet to get things functional, but I'm already impressed with the capabilities and features I've read about after going through the manual.
Here's the deal--What is the minimum I need to get workstations on the private interface to access the public interface (the internet in general). I have pretty much read through the manual from beginning to end, and it most all makes sense. I think I am missing one small detail to get going.
I run a small home network (3 pc's behind the firewall). My private interface is a class 3 subnet with IP 192.168.1.1 and no gateway (it is thet gateway!). My public interface is all DHCP driven by my ISP. From a computer on my private LAN, I can ping both my gateway (192.168.1.1) AND my public interface IP (assigned by my ISP). I can see everything up to and intcluding the public interface. I also know the public interface is viewable from the outside (I can ping and use WebAdmin from work using it's IP -- I will restict access more later when I get things rolling). I have setup masquarading for my eth1 interface to masquarade my eth0_network__.
I haven't bothered with any proxies as it is my understanding that isn't necessary at this point for internal pc's to access the Internet. I also haven't touched routing as I gather the default routes setup should suffice (they appear to be setup fine). My assumption is my rules are not setup properly and that is why I cannot get out. Just for testing purposes I tried to setup a rule of:
Any | Any | Any | Allow
I figured this would allow anything on the inside to access the outside. Unfortunately, that did not happen.
I have done all I know to allow my clients access to the outside world to browse, get email, etc. I can't even ping the outside. I know my client PCs should be work just fine, but they're not (correct IPs, class C subnet just as the internal interface, gateway pointing at the internal interface). Nothing is working. It has to be a setting on the firewall, because as I said, I can pint both interfaces from inside, and from the outside I can access my public interface.
Any guidance as to what I may be missing would be great.
Thanks!
This thread was automatically locked due to age.