Recommend DMZ in answer to FAQ 2

git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@8066 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
This commit is contained in:
teastep 2008-01-14 21:23:20 +00:00
parent 2f96bc5181
commit 54a6755096

View File

@ -476,6 +476,11 @@ DNAT net fw:192.168.1.1:22 tcp 4104</programlisting>
</listitem>
</itemizedlist>
<para>So the best and most secure way to solve this problem is to move
your internet-accessible server(s) to a separate LAN segment with it's
own interface to your firewall and follow <link linkend="faq2b">FAQ
2b</link>.</para>
<para>But if you are the type of person who prefers quick and dirty
hacks to "doing it right", then proceed as described below.<warning>
<para>All traffic redirected through use of this hack will look to