Koozali.org: home of the SME Server

sme as an internal gateway

Nick Slayton

sme as an internal gateway
« on: September 12, 2003, 12:41:45 PM »
i run an adsl router/firewall to my internet conection.this intern routes to my email and web servers in my dmz.i then run the mitel box as an internal gatway/fire wall between my router and the rest of the network
what i want is the rest of my network to be able to to se mdmz as part of the local network with out running a direct network conection to my dmz as this will create a security risk

do i need to add a third network card to my sme or will the sme box pass the request to te router and the router will then pass it on to my dmz and then send any information requested back thru the sme box to my internal network

inside my dmz i run my mail server (a standalone sme box) a crm server (maximizer enterprise) wich unfurtunatly rquires microsoft iis as my web server.

i need to be able to see the crm server as part of the locol netwok

if any one can help thanks in advance

SK

Re: sme as an internal gateway
« Reply #1 on: September 15, 2003, 06:17:37 AM »
In order to simplify things, why don't you run the dmz inside your LAN?

ie on the LAN side of the e-Smith server?

You could use port forward capability to expose the correct connections to the Internet for these servers.



Simplify further ....  You can then do away with the adsl firewall unless it adds some extra functionality (such as keeping the connection logged-in).

Nick Slayton

Re: sme as an internal gateway
« Reply #2 on: September 15, 2003, 07:15:55 AM »
i use therouter as it is cappable of handaling 8 static public ip adresses and it simplifies vpn and provides a hardware firewall
at the moment i use 3 seperate public ips one for our survailance system, one for our website and email and the other secondary hosted website for one of our custemers. the reason why i want to use an internal gateway is just incase some one happens hack into my dmz i then have extra protection on the rest of my network

im hoping that sme in server/gateway mode will be able to act as that internal gateway by alowing requests from the workstation to bass thru the gateway to the router and then to the three servers in my dmz and then back agian as if they were all in the same lan