2 NICs, same subnet for a 'gateway' that won't block traffic from 'outside' NIC
From: freat (rsenykoff_at_harrislogic.com)
Date: 02/27/04
- Next message: Christian Christmann: "proftpd - problems with direcotries"
- Previous message: Martien Verbruggen: "Re: With FTP, who needs samba?"
- Next in thread: Cameron Kerr: "Re: 2 NICs, same subnet for a 'gateway' that won't block traffic from 'outside' NIC"
- Reply: Cameron Kerr: "Re: 2 NICs, same subnet for a 'gateway' that won't block traffic from 'outside' NIC"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Date: 26 Feb 2004 15:06:32 -0800
Here's my problem,
I need to implement QoS for our servers so that the office can handle
video conferencing (currently video conferencing locks up when
replications start, etc). QoS will work wonderfully for this, but the
issue is that we've invested in hardware firewalls / VPN and these
need to handle the external connection. If I simply put in a linux
router behind the VPN appliance, then I'm preventing VPN access to all
the machines on the network behind the linux router.
One option I was thinking, is if the linux box could have 2 NICs and
function as a gateway then I could point everyone at the gateway to
get out, and it would then talk to the VPN appliance. Let's try a
diagram:
Internet
|
|
-----
|VPN|
-----
|
--------
PC------|SWITCH|-------PC
--------
||
---------
|LINUX |
|QoS |
---------
Another thought... can the router be configured to let traffic through
to the other side? Would strange routes have to be set up for people
coming in from the VPN, or just on the VPN box? This would be ideal as
anything coming in would have to go through the QoS box, so the
outgoing traffic would then be shaped.
Something like this:
Internet
|
|
-----
|VPN|
-----
|
---------
|LINUX |
|QoS |
---------
|
--------
PC------|SWITCH|-------PC
--------
I hope these diagrams help. I hope I don't get too many responses like
"MAKE YOUR FIREWALL LINUX!!" and the like... it simply is not an
option. ;)
TIA! -Ron
- Next message: Christian Christmann: "proftpd - problems with direcotries"
- Previous message: Martien Verbruggen: "Re: With FTP, who needs samba?"
- Next in thread: Cameron Kerr: "Re: 2 NICs, same subnet for a 'gateway' that won't block traffic from 'outside' NIC"
- Reply: Cameron Kerr: "Re: 2 NICs, same subnet for a 'gateway' that won't block traffic from 'outside' NIC"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Relevant Pages
|