Hi,
I'm having some trouble setting up a DMZ.
I have 3 NICS in astaro:
eth0 = internal (192.168.2.x private network)
eth1 = external (ISP)
eth2 = DMZ (10.0.4.x private network)
I want to let computers on the DMZ (eth2) to have internet access, but NO access whatsoever to the local LAN (eth0)
DHCP-server is active for DMZ and the computer connected gets an ipadress. But i can't reach the internet at all. I'm not sure if i made the right settings for the network.
What gateway should the DMZ-network have (if any?). The client itself must have a gateway, which? LAN gateway?
I've tried to masquerading the dmz to the external. In packetfilter rules i allowed http out, but still no go.
Anything knows what's wrong here?
If there's an easier way to create a separate private network that cannot access the eth0, please let me know.
Thanks in advance
/ Martin
This thread was automatically locked due to age.