DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

3300V Firewall question

  • joeyconcrete
  • Topic Author
  • Offline
  • New Member
  • New Member
More
29 Aug 2009 09:35 #1 by joeyconcrete
3300V Firewall question was created by joeyconcrete
Is it possible (using the 3300V) to have a true routed DMZ?

e.g.

WAN - Public IP (e.g. 1.1.1.2/30 GW .1)
DMZ - Public IP (e.g. 2.2.2.1/29 GW for clients .1)
LAN - NAT 192.168.1.1/24

2.2.2.0/29 is routed to 1.1.1.1 by the ISP

For instance, services such as SMTP\HTTP\HTTPS can be port-forwarded on the single WAN IP address. The public addressable DMZ can have multiple public facing servers (e.g. VPN, SSL etc) using the available /29 address space.

Then specify firewall rules for traffic WAN->DMZ, DMZ->WAN, LAN->DMZ etc.

The DMZ function has always alluded me on the Drayteks in the past because often the 'DMZ' is simply aliasing\bridging IP addresses from the WAN onto a seperate interface - rather than routing and screening.

Please Log in or Create an account to join the conversation.

Moderators: Sami