Welcome to Firewall.cx - The Site For Networking Professionals

 
Modules
· Home
· Alternative Menu
· Amazon
· Cisco Decrypter
· Cisco Lab Partners
· Feedback
· Forums
· Max Arcade
· Private Messages
· Recommend Us
· Statistics
· Stories Archive
· Submit News
· Surveys
· Topics
· Web Links
· Your Account
 
Cisco Knowledgebase Articles
 
Site Info
Welcome, Anonymous
Nickname
Password
Security Code: Security Code
Type Security Code:

· Register
· Lost Password
Membership:
Latest: Check the profile of Krusty_47 Krusty_47
New Today: 4
New Yesterday: 7
Waiting: 1
Overall: 25794

People Online:
Visitors: 119
Members: 2
Hidden: 0
Total: 121

Online Now:
01: Check the profile of geet Send a quick private message to geet geet
02: Check the profile of S0lo Send a quick private message to S0lo S0lo

We received
75376422
page views since
15th September 2003

Hits New Today: 24386
Hits New Yesterday: 36694
 
Top Downloads
 
Gold Lab Partners


 
Firewall.cx - The Site For Networking Professionals: Forums

Firewall.cx :: View topic - Question Regarding NAT and Subnets
Forums Home
Forum FAQ :: Search :: Memberlist :: Usergroups
Profile :: Log in to check your private messages :: Log in

Question Regarding NAT and Subnets

 
Post new topic   Reply to topic    Firewall.cx Forum Index -> Basic Concepts
View previous topic :: View next topic  
Author Message
Mikele
New Member
New Member


Joined: Sep 10, 2003
Posts: 1
Location: Los Angeles, CA

PostPosted: Wed Sep 10, 2003 7:19 pm    Post subject: Question Regarding NAT and Subnets Reply with quote

Hello

I have a question regarding Subnets. I try to setup NAT for server in Firewall's DMZ so it can connect to database server in firewall's LAN.

This is from the firewall's manual:

"Assign a subnet mask in the DMZ Subnet Mask field. The LAN and DMZ can have the same subnet mask, but the subnets must be different. For instance, the LAN subnet can be 192.168.0.1 with a subnet mask of 255.255.255.0, and the DMZ subnet can be 172.16.18.1 with a subnet mask of 255.255.255.0"

I read your Subnet Masks And Their Effect article.

My questions are:

1) is 172.16.18.1 fall in the network range for Class B? How can a class B be used with Class C ' Default subnet mask?

2) Is it right that the DMZ and LAN should be on different Subnet/Network?

3) For hosting 3 domains on one IIS 5 server, is it right that I should configure 3 LAN's IP address on the Windows 2000 server (with one network card) and then configure One-To-One NAT that bind 3 public IP addresses with 3 LAN IP addresses?

Thank you in advance for your help


=====
Best Regards
Michael
Back to top
View user's profile Send private message
Chris
Founder & Senior Editor


Joined: May 25, 2002
Posts: 1208
Location: Thessaloniki, Greece

PostPosted: Fri Sep 12, 2003 11:05 am    Post subject: Question Regarding NAT and Subnets Reply with quote

Michael,

Answering in order your questions:

1) the 172.16.18.1 IP Address does fall into the Class B range and the default subnet mask is 255.255.0.0.

The IP Addresses indicated on the manual as you posted, are clear examples to help you understand one type of way you can setup the machines in the DMZ zone.

The Class of IP Addresses you use in your DMZ or LAN zone depend on your network setup. If there is a gateway of some sort that hides the whole network from the internet, then your free to choose whatever class and subnetmask that suites your needs, which is the case for the example you provided.

The method of using a different subnetmask other than the default is called CIDR, and is covered on this site.

Because a Class B network gives you more IP Addresses than what you need, you divide that Class B network into smaller ones by using a different subnetmask. All ISP's use this method to help preserve the availability of IP Address on the Internet, and companies now use this method for the same reason, but to preserve IP addresses within their own private network and also to make it easier to manage.

2) DMZ zones MUST be on a different subnet or network. Having them on the same defeats the purpose of their existance.
Please read the DMZ zone page for more information.

3)The simplest way to host multiple domains is to point the NS (name server) records in the dns configuration panel of the company which they were bought to the public ip address of the windows 2000 server. Of course there are a few different options here... you can either point only the Cname www records (alias) to the w2k server so the server only deals with the websites for these domains, or you can choose to move the whole DNS structure for these sites to the win2k server, in which case you will need to setup a fully functional DNS server for these domains.

Let us know if there are certain areas which are still unclear.

Cheers,
Back to top
View user's profile Send private message Visit poster's website MSN Messenger
Display posts from previous:   
Post new topic   Reply to topic    Firewall.cx Forum Index -> Basic Concepts All times are GMT + 2 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
© Copyright 2000-2009 Firewall.cx - All Rights Reserved

Copyright of all documents and images belonging to this site by Firewall.cx. Information contained on this site is copyrighted material. It is illegal to copy or redistribute this information in any way without the written consent of Firewall.cx

Firewall.cx disclaims any responsibility for software and information obtained through this site or its links.

Page Generation: 0.455 Seconds