Re: DHCPCD on an internal LAN



On 2007-12-10, Mike <Not@xxxxxxxxxxx> wrote:
Quite the opposite. I don't want the LAN machines to ever connect to
the internet at all. The only machine that should ever connect to the
internet should be the P2 machine. All others on the LAN should only
be able to SSH into an account on the P2 and run P2 applications
remotely via SSH to surf etc. Therefore, only one machine ever goes
online (the P2), and only one internet connection required. And, each
internal LAN machine should remain isolated from any other on the
LAN. A kind of "blind tentacle" arrangement with the P2 as head.

Hope you don't have any unix prodigies on the client side; I can
think of at least two ways to fool p2 computer and let clients to use
the Internet directly :) One would be a ssh tunnel, the other could be a
small python/perl script that would act as a proxy :)

I guess you should add some L7 filtering to the p2 machine ;)
--
Ignorance has taken over
Yo, we gotta take the power back!
-- Rage Against The Machine, Take the power back

.



Relevant Pages

  • Re: packet loss to firewall while Internet link is down
    ... When the Internet link goes down, ssh refuses ... to allow connection from within the LAN to our BSD ... When the Internet is down, the CPU load factor on the ...
    (freebsd-questions)
  • packet loss to firewall while Internet link is down
    ... When the Internet link goes down, ssh refuses ... to allow connection from within the LAN to our BSD ... When the Internet is down, the CPU load factor on the ... FreeBSD firewall is low, but the number of TCP packets ...
    (freebsd-questions)
  • Re: SSH attack
    ... then I don't see how you can safely use ssh at all. ... >> scrutinized, stripped and locked down, dedicated (internet) ssh server, ... I first got the idea from ISPs which allow remote control of customer ... For example, I might use a modem on a system with no LAN connection, ...
    (Debian-User)
  • Re: Moving Exchange Server
    ... Placing them in the LAN gives internal users 100% access with no firewall to ... DMZ, thus 0% risk/ports open between them. ... If Microsoft Exchange and/or Active Directory cannot run ... >> Internet is better? ...
    (microsoft.public.exchange.setup)
  • RE: Firewall Rule Set not allowing access to DNS servers?
    ... > My LAN is configured with static IP addresses, ... > I have full connectivity with the internet from every machine on my ... > # Allow out access to my ISP's Domain name server. ... > # Interrogate packets originating from the public internet ...
    (freebsd-questions)