iptables firewall between dsl router and intranet

From: Thomas Olschewski (junk_at_innomic.de)
Date: 07/27/05


Date: Wed, 27 Jul 2005 08:31:54 +0200

Hello,

I had setup a iptables based linux firewall. It was connected with eth0 to
the internal network and with eth1 to a dsl modem (pppoe) and did also all
the NAT stuff. A lightning strike blows my modem and the new dsl hardware is
a router itself, providing NAT, voip etc. Nevertheless I would like to use
my iptables firewall between this router and my internal network.

Internal network is 192.168.5.x

Questions
Is it a good idea to set the unsecure nic eth1 of the firewall and the dsl
router to another net, for instance 192.168.6.x?
How are the machines of the internal network routed? Is the gateway ip the
ip of the firewall's secure nic eth0? I suppose it is, but how is the
firewall networking setup? Does it need also a gateway ip, the ip of the dsl
router? Can this be the default route or do I have to setup different routes
for eth0 and eth1?

I hope someone can enlighten me.

Thomas



Relevant Pages

  • [SLE] DHCP Firewall DMZ issues
    ... I'm having some very strange SuSE Firewall behavior in version 9. ... I have eth1 set as the internal network and eth2 as the DMZ. ... but no external connections are possible. ...
    (SuSE)
  • Re: SuSEfirewall2 question
    ... > modem and eth1 acts as a gateway connected to an internal network. ... > able to see the internet from machines on the internal network with ... which the firewall is running using the IP address of eth1. ...
    (alt.os.linux.suse)
  • Re: Inline firewalls vs. Inline firewalls "spaced out"
    ... You internal network should only be able to talk outwards, ... the first design. ... a third firewall has to be compromised. ... > greater security to your web boxes than the first design. ...
    (Security-Basics)
  • RE: Proxy & Firewall Implementation
    ... Put a firewall between your internal network and the DMZ which allows ... DMZ servers to the gills. ...
    (Security-Basics)
  • Re: OT udp port 138 BROWSER traffic
    ... >>potential problems with people outside the firewall looking at disk info ... > point of changing dsl providers. ... > issues that are interfering with my connection at their end. ... > firewall/router and their gateway, ...
    (comp.os.linux.security)