From owner-freebsd-net@FreeBSD.ORG Sat Oct 1 19:16:38 2011 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 8D726106566B for ; Sat, 1 Oct 2011 19:16:38 +0000 (UTC) (envelope-from marek_sal@wp.pl) Received: from mx4.wp.pl (mx4.wp.pl [212.77.101.8]) by mx1.freebsd.org (Postfix) with ESMTP id 069D48FC12 for ; Sat, 1 Oct 2011 19:16:37 +0000 (UTC) Received: (wp-smtpd smtp.wp.pl 20416 invoked from network); 1 Oct 2011 21:16:35 +0200 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=wp.pl; s=1024a; t=1317496595; bh=05feFn/zw2mxwVoyzVgnpL+9vkRSkNHfglX52GFGXj4=; h=From:To:Subject; b=tVtg9Idzli/WWgc5YB4MdzlWAPQ1dJtcJ/PfhUkDGBeXPiAyInh/HDSa2CXmRTWSg dzA6JNVRHm0XQEIPXjiMNRltsU0tL6EctLvwwB/JAFKZ/IJpEccCqMTUUfAgstCCwT +e/Q0m7Iw91Ner1rl67PnPJK9Ps5673ebHNlDpxg= Received: from cwx170.internetdsl.tpnet.pl (HELO [10.0.0.15]) (marek_sal@[83.19.131.170]) (envelope-sender ) by smtp.wp.pl (WP-SMTPD) with SMTP for ; 1 Oct 2011 21:16:35 +0200 Message-ID: <4E876705.3040806@wp.pl> Date: Sat, 01 Oct 2011 21:16:21 +0200 From: Marek Salwerowicz User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:7.0) Gecko/20110922 Thunderbird/7.0 MIME-Version: 1.0 To: Freddie Cash , freebsd-net@freebsd.org References: <4E412116.1070305@wp.pl> <4E422A74.3090601@wp.pl> <4E7B450F.5050802@wp.pl> <4E84B447.7010509@wp.pl> <4E84DE26.6030103@misal.pl> <4E85D8CB.6010104@wp.pl> In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-WP-AV: skaner antywirusowy poczty Wirtualnej Polski S. A. X-WP-SPAM: NO 0000000 [8fO0] Cc: Subject: Re: ipfw - accessing DMZ from LAN X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 01 Oct 2011 19:16:38 -0000 W dniu 2011-09-30 17:44, Freddie Cash pisze: > > that's the correct behaviour, as the public IPs are physically assigned to > the interfaces on the router. Thus, connecting to the public IPs from the > router ... will connect to the router. > > You need to ping the private IPs from the router, since the router is > directly connected to the private networks. > And how about pinging from other DMZ host to DMZ host (both are in the same subnet) ? Am I able to allow them to contact using public IPs? Regards, -- Marek Salwerowicz