I always thought it was necessary to create DNAT's from public IP's (additional addresses) to DMZ hosts and also need to have a masquerading (or SNAT) rule from these hosts to the internet.
I just read another thread however which seems to assume it's possible to directly use the public IP on a host in DMZ.
Is this indeed correct?
If yes, how should it be configured (subnet on DMZ?, additional addresses on the interface?)?
This thread was automatically locked due to age.