DSL ................. T1
_|......................|__
| ............................|
|.............................|
|........................... |
|.........................|
LAN ................DMZ
The DSL is the default GW, that way the proxy will pull HTTP/FTP from the DSL. I have a policy route and masquerading setup so that the DMZ will use the T1 for internet traffic. All of that works fine my problem is this. I cannot get DNAT to work from any public address on the T1 to my DMZ, or LAN for that matter. I have a feeling I missed something simple and already spent about an hour searching for a solution.
Without a DNAT rule I see a DROP line in my logs as there should be. As soon as I enable a dnat rule to go from one of my public T1 address to a DMZ machine, I dont get any event ACCEPT or DROP in my packet log.
Any input would be greatly appreciated!
This thread was automatically locked due to age.