Networking Forums

Networking Forums > Computer Networking > Linux Networking > Setting up public IP inside firewall: possible?

Reply
Thread Tools Display Modes

Setting up public IP inside firewall: possible?

 
 
Max
Guest
Posts: n/a

 
      09-06-2007, 12:59 AM
I have...
- one computer that runs Endian Firewall (EFW)
- one server that runs Linux and virtualized systems
- client computers (Linux, Mac and Windows) on the rest of my network

I want to...
- use EFW at the edge of my network for its monitoring features and
its easy to setup VPN
- make my Linux server publicly accessible

My ISP gives me one (1) static IP address on my cable modem; I can get
more addresses if I pay more (20$/month). I would like, if possible,
to give the Linux server its own IP address and still be able to
monitor it with EFW.

The simple setup would be to connect the Linux server and the EFW to a
switch connected to the cable modem. However, that setup would NOT
allow me to monitor traffic to the server with EFW.

The ideal setup would be to route the traffic through EFW, to a kind
of DMZ; is that possible?

Thanks,
Max

 
Reply With Quote
 
 
 
 
Max Plante
Guest
Posts: n/a

 
      09-07-2007, 01:14 AM
UPDATE:

Am I on the right track if I assume you can bridge two NICs together to
accomplish a transparent DMZ for the server?

Thanks,
Max

P.S.: A diagram of the network will follow in another message.



On 2007-09-05 20:59:02 -0400, Max <(E-Mail Removed)> said:

> I have...
> - one computer that runs Endian Firewall (EFW)
> - one server that runs Linux and virtualized systems
> - client computers (Linux, Mac and Windows) on the rest of my network
>
> I want to...
> - use EFW at the edge of my network for its monitoring features and
> its easy to setup VPN
> - make my Linux server publicly accessible
>
> My ISP gives me one (1) static IP address on my cable modem; I can get
> more addresses if I pay more (20$/month). I would like, if possible,
> to give the Linux server its own IP address and still be able to
> monitor it with EFW.
>
> The simple setup would be to connect the Linux server and the EFW to a
> switch connected to the cable modem. However, that setup would NOT
> allow me to monitor traffic to the server with EFW.
>
> The ideal setup would be to route the traffic through EFW, to a kind
> of DMZ; is that possible?
>
> Thanks,
> Max




 
Reply With Quote
 
Max Plante
Guest
Posts: n/a

 
      09-07-2007, 11:56 AM
It seems the attachment did not get through!

Here is a convinient link to the diagram:
http://picasaweb.google.com/Maxime.P...28243122866082

Cheers,
Max

On 2007-09-06 21:14:08 -0400, Max Plante
<Maxime.Plante+(E-Mail Removed)> said:

> UPDATE:
>
> Am I on the right track if I assume you can bridge two NICs together to
> accomplish a transparent DMZ for the server?
>
> Thanks,
> Max
>
> P.S.: A diagram of the network will follow in another message.
>
>
>
> On 2007-09-05 20:59:02 -0400, Max <(E-Mail Removed)> said:
>
>> I have...
>> - one computer that runs Endian Firewall (EFW)
>> - one server that runs Linux and virtualized systems
>> - client computers (Linux, Mac and Windows) on the rest of my network
>>
>> I want to...
>> - use EFW at the edge of my network for its monitoring features and
>> its easy to setup VPN
>> - make my Linux server publicly accessible
>>
>> My ISP gives me one (1) static IP address on my cable modem; I can get
>> more addresses if I pay more (20$/month). I would like, if possible,
>> to give the Linux server its own IP address and still be able to
>> monitor it with EFW.
>>
>> The simple setup would be to connect the Linux server and the EFW to a
>> switch connected to the cable modem. However, that setup would NOT
>> allow me to monitor traffic to the server with EFW.
>>
>> The ideal setup would be to route the traffic through EFW, to a kind
>> of DMZ; is that possible?
>>
>> Thanks,
>> Max




 
Reply With Quote
 
Pascal Hambourg
Guest
Posts: n/a

 
      09-07-2007, 02:44 PM
Hello,

Max Plante a écrit :
>
> Am I on the right track if I assume you can bridge two NICs together to
> accomplish a transparent DMZ for the server?


Yes, this is one possible solution. What kind of monitoring are you doing ?
 
Reply With Quote
 
Max
Guest
Posts: n/a

 
      09-07-2007, 05:29 PM
On Sep 7, 10:44 am, Pascal Hambourg <boite-a-s...@plouf.fr.eu.org>
wrote:
> Hello,
>
> Max Plante a écrit :
>
>
>
> > Am I on the right track if I assume you can bridge two NICs together to
> > accomplish a transparent DMZ for the server?

>
> Yes, this is one possible solution. What kind of monitoring are you doing?


Basically, I like Endian Firewall (EFW)'s ntop monitoring web
interface, which shows very detailed per-protocol traffic stats. There
is also interesting intrusion detection (snort) and the traffic
shaping features.

This could also be done with m0n0wall I believe (can anyone confirm?),
but I have no experience with it. Anyway, I'd rather use a firewall
distribution than setup a custom Linux or BSD solution, since the
former is quicker to setup and upgrade.

I have found this concise documentation about m0n0wall:
http://doc.m0n0.ch/handbook/examples...ed-bridge.html

Does anyone know if that solution is adequate if:
1) the ISP hands out IP addresses without a netmask?
2) I use Endian Firewall? If so, how?

Thanks,
Max

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Problem setting up ftp server inside lan (iptables) Sam Linux Networking 1 08-16-2004 09:26 PM
Connect public IP from inside - IPTables Marv Linux Networking 1 03-04-2004 01:07 AM
public IP from inside the LAN templeton Linux Networking 0 01-20-2004 03:42 PM
Iptables: How do I forwarding public IPs into a router inside a privateIP network? Stephen Hurrell Linux Networking 1 11-22-2003 10:17 PM
iptables: redirecting packets inside a firewall pete@mynix.org Linux Networking 3 09-04-2003 08:06 AM



1 2 3 4 5 6 7 8 9 10 11