port forwarding and ip-less firewall

Edison Cala edison at sflu.com
Wed Feb 25 01:19:46 PST 2004


hello list!

i want to ask some help on port forwarding in a bridge-firewall network.

our network setup is:

1. the router is outside the firewall, direct to the internet.
2. the bridge-firewall computer (2 ethernet cards installed, eth0 - outside (router), eth1 - protected network) is between the router and the protected network.

all the servers are behind the firewall and only opened the allowed ports. i have 2 mail servers (unit1.domain.com and unit2.domain.com) running on the protected network, unit1.domain.com is just an smtp relay for unit2.domain.com and its working fine. however, i want to put a rule (port forward) in firewall to forward request destined to unit2.domain.com (port 25), but that request should be first passed to unit1.domain.com (for antispam processing) before unit2. unit1 should then be the one to forward the request to unit2.domain.com.

why i want to do this is that, some mails are getting through and received at unit2 without passing to unit1. in mx, unit1 is the 1st prio and unit2 is 2nd prio only.

please help and give an idea on port forwarding rules between two servers within the protected network.

thank you!

edison cala


More information about the freebsd-questions mailing list