Networking Forums

Networking Forums > Computer Networking > Windows Networking > Need help setting up an IDS and VPN server...maybe firewall.

Reply
Thread Tools Display Modes

Need help setting up an IDS and VPN server...maybe firewall.

 
 
news@celticbear.com
Guest
Posts: n/a

 
      05-11-2005, 09:09 PM
I think basic topography issues will determine what I can do here. But
here's what I have, and then what I need, what I think I can do, and
then my request for a severe beating...I mean, help with simply how to
get started. =)

We have a small business with about 10 WinXP (Home) PC's, a Mac, two
Fedora Core PC's and a FC fileserver.
These are all connected to one switch (without a sensing or span port).
And this is connected to the router/NAT/firewall provided by our
ISP/DSL providor for our business.
It's this NAT(?) that is giving the 192.168.1.* IP's and blocking ports
from the Internet side.

What I need to do, is insert a machine between the ISP's NAT and the
switch to
a) Be a VPN server to allow a remote employee access to file shares
internally
b) Be an IDS box with Snort to track and monitor traffic entering and
leaving the network.

What I first thought was that I could have this machine, RedHat 9 is
what it will have, to be a Primary Domain Controller, but since some
users are using WinXP Home, they can only workgroup.

So here's my question: Is it possible, for this RH 9 PC with two NICs
to be able to be between the ISP NAT and the switch? Allow the ISP NAT
to provide IP's (actually, I'm forcing the PC's to use static IP's, but
that's beside the point,) to itself and all other PC's, while still
monitoring traffic?

Maybe because it has to..."pass through"(?), it can't really be a
firewall, but monitoring? I gather the NIC on the NAT side will get an
IP from that NAT, but what about the NIC on the switch side? How does
that work?
CAN the PC be a NAT itself without having to be a PDC? Can the PC's on
the switch still get IP's from this new machine without it being a
domain?

Thanks for ANY advice, pointers...just looking for suggestions of where
to start looking and what to look for.
Thanks,
Liam

 
Reply With Quote
 
 
 
 
Layoff_IT
Guest
Posts: n/a

 
      05-11-2005, 09:36 PM
Ah, there are still lots of layoff IT people out wanting jobs.

Your other option is to get yourself an Indian student to answer your
questions for free.

Best of luck.
 
Reply With Quote
 
news@celticbear.com
Guest
Posts: n/a

 
      05-11-2005, 09:42 PM
Layoff_IT wrote:
> Ah, there are still lots of layoff IT people out wanting jobs.
>
> Your other option is to get yourself an Indian student to answer your
> questions for free.


Why, that was not the least bit helpful. Thank you. =)
Usenet/newsgroups ARE free, last I checked (or else I have one HUGE
bill coming!) and I really don't care the nationality of the person who
helps me out. They can be an out of work Muslem Eskimo with family ties
to Brazil for all I care.
Thanks,
Liam

 
Reply With Quote
 
TweetyB
Guest
Posts: n/a

 
      05-12-2005, 06:23 AM
Take a look at IPCOP as a replacement for that NAT box. It will provide
NAT, Firewall, IDS / snort, IPSec VPN endpoint/server , DHCP server etc.

It's based on LFS (Linux from scratch) release under GPL. Just Google for
it.

Cheers

 
Reply With Quote
 
news@celticbear.com
Guest
Posts: n/a

 
      05-12-2005, 02:17 PM

TweetyB wrote:
> Take a look at IPCOP as a replacement for that NAT box. It will

provide
> NAT, Firewall, IDS / snort, IPSec VPN endpoint/server , DHCP server

etc.
>
> It's based on LFS (Linux from scratch) release under GPL. Just Google

for
> it.
>
> Cheers


Whoa! That looks like EXACTLY what I need! I'm going with that--thanks
for the tip!
I've looked around on the site, and I can't seem to find any
minimum/recommended hardware requirements. Even the link to the
compatible hardware list is broken.
Any idea how it will run on:
AMD Duron 166 MHz
50MB RAM
3GB HD?

It's not much, but I figure if it doesn't use X-windows, then it should
be enough.

Thanks!
Liam

 
Reply With Quote
 
TweetyB
Guest
Posts: n/a

 
      05-12-2005, 08:03 PM
AMD Duron 166 MHz
50MB RAM
3GB HD?

No Problem. I run it on a P166, 32Mb, 2G HDA.

It is a little slow if U install COP+ with Dansguardian and the firewall
logs aren't that quick. Works like a charm on a K6-2 450 though.

cheers

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Server 2008 with Hyper-V - domain controller - Firewall GUI's show firewall ON, but netsh reports firewall OFF Bruce Sanderson Windows Networking 7 10-07-2008 09:57 AM
Advice for setting up a firewall LinuxMercedes Linux Networking 5 06-06-2008 06:00 PM
my firewall setting are messed up DAWUD_WALLACE@HOTMAIL.COM Wireless Networks 1 12-07-2007 03:22 PM
Need help setting up an IDS and VPN server...maybe firewall. news@celticbear.com Linux Networking 0 05-11-2005 09:09 PM
Setting up a Firewall Basile STARYNKEVITCH Linux Networking 11 11-14-2003 08:07 AM



1 2 3 4 5 6 7 8 9 10 11