PDA

View Full Version : DMZ Issue - DMZ is scanning packets


Brainz
04-02-2007, 06:22 AM
Packets behind the DMZ are still getting scanned by untangle??

(scenario)
3 Linux servers are plugged into a switch that is plugged into the DMZ network port of the Untangle router. The port goes straight into the public wan side of our network and the servers get IPs from a DHCP server there... So that portion works correctly.. The issue arises when we try to run updates on the Linux Fedore Core servers. The updates are getting blocked.. When we take Untangle out of the loop, it works again.. Is this not a true DMZ? Are there settings that we're missing that tell the DMZ to not only allow the IP's and such to not be routed but also not be scanned by untangle? Otherwise the DMZ will be useless if it continues to be scanned with the services of Untangle blocking the downloads from occurring.. Thanks.

Joey

gotkimchi
04-02-2007, 04:47 PM
Brainz (Joey),

Great question, to set this up, goto the policy manager. Drop down (default rack) Click on the Show Policy manager, default policies. Change the DMZ to external and external to DMZ to "no rack" meaning don't scan anything.

tony

Brainz
04-12-2007, 06:58 AM
Thanks.. This worked prefect!