Subject: new NetBSD firewall
To: NetBSD <netbsd-help@netbsd.org>
From: None <fernando@rxp.com>
List: netbsd-help
Date: 06/22/2003 18:15:57
hello there.
i'm about to put together a old box and use it as a firewall and nat. i
currently have 2 machines. one is a win2k server acting as a nat for the
other and as a dns server for web sites off location. i'm not sure that if i
set up the netbsd box, if my dns server will continue to answer queries from
the web. should i install bind on the netbsd box since it will be taking
over the public ip address (i don't know how to do that;-)? or should i just
forward port 53 through netbsd to the win2k box? will i see a big hit in
performance using the fowarding?

also, when i set up the new nat/firewall, i don't want to disconnect the dns
server until i am ready with the netbsd box. but the only way i have to
install it now is the NetBSD Firewall Project, wich uses two floppies to
setup the nics, then downloads the rest of netbsd (minimal for fw). this
long download will mean my dns will be off line. one of the configurations
(iirc) is to use a dynamic ip. if i use that to set up, and just let it
download the setup THROUGH my current nat (the win2k box) then complete the
install that way, will it be hard to change it from dynamic to static? i
can't seem to find on the web the info to change the nic configuration to
static and asign the ip address that the isp gave to me.

thanks folks. sorry about so many stupid questions. :-)

Fernando