Koozali.org: home of the SME Server

Setting up DMZ

matt001

Setting up DMZ
« on: November 24, 2005, 10:41:14 AM »
Hi Guys

I have got a static IP for my internet connection, and looking at getting another 4 more static ip addresses, now how do I setup SME Server 6.0.1 with DMZ, So I can have the new ips in DMZ say for example

202.1.2.0 (Public Static IP) forwards to 192.168.0.5 (Internal Network)

How do I do this.

Offline idp_qbn

  • *****
  • 347
  • +0/-0
Setting up DMZ
« Reply #1 on: November 24, 2005, 03:27:54 PM »
Hello...I think you want to put too many eggs in the one basket.

My preferred method is to use a dedicated firewall, not SME.
I recommend Smoothwall or IPCop, both of which are excellent firewall systems (small, free, work on minimal systems) which provide DMZ facility easily.

I use a P400 with 128Mb RAM and 8Gb HDD which handles 10 users really well.

Both have VPN ability, but IPCop especially can have OpenVPN (www.openvpn.net) to give you external access....and there are contribs here on how to do it with SME which are probably transposable to IPCop. I guess Smoothwall can use OpenVPN too, but is more tightly controlled about updates (which might knock out the OpenVPN).

Cheers :-D
___________________
Sydney, NSW, Australia

matt001

Setting up DMZ
« Reply #2 on: November 24, 2005, 11:16:38 PM »
For the moment, I want to be able to use sme server for both, as I don't have a spare old pc at the moment.

And I really don't want to go and install another distro when I am happy with what SME does except, I need the setup DMZ with sme Server.

Is their a contrib that can do this for me.

Offline MSmith

  • *
  • 675
  • +0/-0
Setting up DMZ
« Reply #3 on: November 25, 2005, 02:19:29 AM »
Actually there isn't an easy way to do this, as your search has no doubt revealed.  SME is not designed for exposing an internal host or hosts to the Internet and has no provisions for adding that functionality.
Your best bet is to do as idp_qbn suggests and go with a firewall distro that is designed to support what you want.  You can most likely go to a thrift shop and get a PC that will run Smoothwall or IPCop for $20 USD.
...