Lars Erik Dangvard Jensen wrote: > > Or is it possible to DNAT to at public IP from the public IP itself? > > DNAT inet1:PUBIP inet1:PUBIP:25 tcp 2525 - PUBIP >
Yes. But assuming that the Proxy arp'd system with 'PUBIP' is in a local zone (say 'DMZ'), the rule would be: DNAT inet1 DMZ:PUBIP:25 tcp 2525 - PUBIP -Tom -- Tom Eastep \ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EMAIL PROTECTED] PGP Public Key \ https://lists.shorewall.net/teastep.pgp.key
signature.asc
Description: OpenPGP digital signature
------------------------------------------------------------------------- This SF.net email is sponsored by: Microsoft Defy all challenges. Microsoft(R) Visual Studio 2005. http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/
_______________________________________________ Shorewall-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/shorewall-users
