Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Astaro Gateway Products > Management, Networking, Logging and Reporting

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 02-08-2010, 11:48 PM
Member
 
Join Date: Feb 2010
Posts: 31
Default IP Alias Question

So...

If I have a x.x.x.14 / 29 subnet and I have no idea how anything is working. The current PIX firewall is configured to forward the following IPs:

x.x.x.15
x.x.x.16
x.x.x.17
x.x.x.18

...and a gateway of x.x.x.13. This is fine with me but none of the subnet calculators coincide with this math. Regardless, I am wondering how to configure my Astaro firewall.

1) Should I just add the interface with the x.x.x.14 / 29 IP address?
2) If so, do I then create an x.x.x.x / 32 alias for each IP (or will the #1 item do this implicitly)?

Any help is appreciated (I will buy you a pint if you can make this work).
Reply With Quote
  #2 (permalink)  
Old 02-09-2010, 01:04 AM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 6,999
Default

The Astaro really does make this pretty simple, but there's still a lot to know. We can give you some ideas, but, in a professional environment, I think it makes good economic sense to have your first Astaro installed by someone with experience. That said, here are a few thoughts.

If you have an internal mail server and plan to use the Astaro SMTP proxy (with or without mail security), then to the External interface, you should assign as the primary IP the address pointed to by the MX record in your authoritative name server.

For the other IPs, they may be assigned as 'Additional Addresses' on the External interface, and each should indeed be given /32. There is no default gateway assigned to an additional address.

For example, to make an internal web server available to the internet, you would create a NAT rule:
Traffic Source: Internet
Traffic Service: HTTP
Traffic Destination: External [{name of add'l address}] (Address)

NAT mode: DNAT (Destination)

Destination: {host name of internal IP of webserver}
Destination Service: {leave blank!}
Cheers - Bob
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 02:19 AM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.