Specifications

80.80.80.1. The DNS service is available from the provider under the IP
addresses 123.123.123.123 and 123.123.123.124. The following entries
have already been made:
www.example.com = 80.80.80.2 + example.com
ftp.example.com = 80.80.80.2
mail.example.com = 80.80.80.2 + MX record
cvs.example.com = 80.80.80.12
Because hosts addressed via proxy services of the firewall do not require
public IP addresses, two networks are administrated in the DMZ:
80.80.80.8/255.255.255.248 services without proxy (CVS)
192.168.8.8/255.255.255.248 services with proxy (web, FTP, mail)
The servers in the proxy network in the DMZ receive the IP addresses:
web server = 192.168.8.9
mail server = 192.168.8.10
FTP server = 192.168.8.11
The network 192.168.10.0/255.255.255.0 is intended for the connec-
tion to the internal network for staff at the headquarters.
The Branch in Frankfurt
In Frankfurt, only a small network is available with real IP addresses. The
address space 100.100.100.0/255.255.255.252 also includes the router
of the ISP with the IP address 100.100.100.1. The DNS is also managed
here by the provider. The following entry was agreed:
ftp2.example.com = 100.100.100.2
Internally, the network 192.168.11.0/255.255.255.0 is intended for
staff.
The Branch in Munich
Munich, which is a small branch, only has a DSL connection to the Internet.
There is only one fixed IP address here: 120.120.120.1
The network 192.168.12.0/255.255.255.0 is used internally for the Mu-
nich location.
40 Using the FAS