HELP (how-to): SnapGear (embedded Linux) Firewall config for public class c network

From: Lazza (wilson_larry_at_hotmail.com)
Date: 08/22/03


Date: 22 Aug 2003 10:24:13 -0700

I am trying to set up a SnapGear SME530 (an embedded linux firewall)
as a router and firewall from an ADSL service (TPG) with a /30 network
address for the router external I/F routing to a public class c
address space on the LAN side. This is shown below:

Internet
 |
 |
 |
 ----ADSL ISP GW address
 | 220.x.y.149/30
 |
 |
 ----ADSL modem in bridge mode RFC1483
 | admin I/F 203.a.b.253 (currently)
    |
 ----Router/FW (SnapGear SME530)
 +WAN Port-> 220.x.y.150/30 (Ext. Router Port )
  [*]
 +LAN Port-> 203.a.b.1/24 (Int. Router Port )
 |
 |
 |--------------------------------------
    | | |
   203.a.b.2 203.a.b.100 etc

>From the SME530, I can ping WAN & LAN Interfaces, ISP gateway, any
internet address, LAN hosts.
>From the LAN I can only ping the LAN gateway. Can ping other LAN
hosts.
>From the Internet I can only ping the router/FW (SME530) WAN
interface.

What do I have to do to get the SME530 to pass traffic (TCP, UDP,
ICMP) from the Internet to servers on the LAN and visa-versa?

I also need to set up firewall rules to restrict traffic to WWW, SMTP,
POP3 from the internet to specific hosts only.

Any config suggests, esp how-to would be greatly appreciated.

Regards & Thank You in advance.
Lazza

P.S. I know the ADSL modem admin I/F should probably be on a private
IP address



Relevant Pages

  • Re: Changing the Default Gateway
    ... I agree that I can't see how the WAN side of the router would have anything ... is saying that the folks changed the internal LAN IP of the router to .222. ... this new MPLS internet connetion and phase out the Frame router. ... All tests passed on this DNS server ...
    (microsoft.public.windows.server.sbs)
  • Re: 3 LAN, 2 WAN - 2 LAN use 1 WAN, last LAN uses other WAN
    ... Internet over different paths after that. ... With a single LAN Router for all the segments, ... Then each "business" uses the Firewall they are supposed to use for the ...
    (microsoft.public.windows.server.networking)
  • RAS - Routingproblem? DNS? Wins?
    ... ging übers Kabelmodem ins Internet und die andere ins LAN. ... Adapter und über diesen nam der Router externe Anrufe unseres Aussenlagers ... anderen PCs ganz normal mit 1 Netzwerkkarte im LAN angehängt ist. ...
    (microsoft.public.de.german.windowsxp.networking)
  • RAS - Routingproblem? DNS? Wins?
    ... ging übers Kabelmodem ins Internet und die andere ins LAN. ... Adapter und über diesen nam der Router externe Anrufe unseres Aussenlagers ... anderen PCs ganz normal mit 1 Netzwerkkarte im LAN angehängt ist. ...
    (microsoft.public.de.german.windowsxp.networking)
  • HELP (how-to): SnapGear (embedded Linux) Firewall config for public class c network
    ... I am trying to set up a SnapGear SME530 (an embedded linux firewall) ... as a router and firewall from an ADSL service with a /30 network ... address space on the LAN side. ... internet address, LAN hosts. ...
    (comp.os.linux.security)