Networking Forums

Networking Forums > Computer Networking > Linux Networking > Router wiht 2 in's and 1 out

Reply
Thread Tools Display Modes

Router wiht 2 in's and 1 out

 
 
Luiz Borges
Guest
Posts: n/a

 
      04-12-2006, 07:43 PM
I have a network (let's call it A) connected to a server running
BrazilFW as a router to the internet. Everything works fine, the
connection is shared without problems.
Now I need to connect a second network to the internet (call it B), but
the network must be isolated from A, so I can't just plug the hub of B
on the hub of A...

>From that point I come up with those options:

1) A firewall between B and the hub of A to restrict all traffic to the
server only.

2) Put a third NIC on the server. But I don't know if BrazilFW works
with that.

3) Use a switch to connect the Server, A, and B, and them program the
switch to allow only A<=>Server and B<=>Server.

I don't know if all (or any) of these options will really work, those
were the first things that come up to my mind. Any more suggestions are
welcome.

Thanks in advance,
Luiz Borges

 
Reply With Quote
 
 
 
 
Moe Trin
Guest
Posts: n/a

 
      04-14-2006, 12:25 AM
On 12 Apr 2006, in the Usenet newsgroup comp.os.linux.networking, in article
<(E-Mail Removed). com>, Luiz Borges wrote:

>I have a network (let's call it A) connected to a server running
>BrazilFW as a router to the internet. Everything works fine, the
>connection is shared without problems.
>Now I need to connect a second network to the internet (call it B), but
>the network must be isolated from A, so I can't just plug the hub of B
>on the hub of A...


Sorry, I'm not familiar with BrazilFW. Network "A" and "B" - are they
using "real" addresses, or RFC1918 (such as 192.168.x.y)?

>From that point I come up with those options:
>1) A firewall between B and the hub of A to restrict all traffic to the
>server only.


While this prevents "A" from accessing "B" and vice-versa, this doesn't
prevent someone on the router side of the firewall from "hearing" all
Internet traffic.

>2) Put a third NIC on the server. But I don't know if BrazilFW works
>with that.


A quick google search doesn't say one way or the other, though I don't
see why this wouldn't work. I've seen small firewalls such as these used
for "internal" and "DMZ" zones from a common external interface. That
_should_ be enough.

>3) Use a switch to connect the Server, A, and B, and them program the
>switch to allow only A<=>Server and B<=>Server.


That would work

>I don't know if all (or any) of these options will really work, those
>were the first things that come up to my mind. Any more suggestions are
>welcome.


They look good. Minor problem will be routing - in choice 1, the BrazilFW
would have to know to route traffic through the firewall (unless it were
a transparent bridge). For choice 2, if that doesn't work, putting in a
more capable firewall would certainly do the job. This might be a low
end PC with multiple NICs running a router/firewall distribution, or
even a regular Linux that has been rigorously stripped of unneeded
software.

Old guy
 
Reply With Quote
 
Luiz Borges
Guest
Posts: n/a

 
      04-14-2006, 04:14 AM
The best option for me would be #2, add another NIC.. but as far as I
know (and as far as I searched) that doesn't work right in BrazilFW..

Now I looking for another router/firewall based distro, I've found
Devil Linux but it seemed too strange, and I don't know it's real
capabilities.

Any other options on router distros? preferably on LiveCD or floppy...

Luiz Borges

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
sending message to another vlan wiht "net send" majid asadpoor Windows Networking 4 05-30-2007 05:17 PM
Deleting all dchp-scopes wiht one command Petri S Windows Networking 0 09-14-2006 05:37 AM



1 2 3 4 5 6 7 8 9 10 11