Re: Is this a wise configuration?



On Fri, 28 Apr 2006 14:34:28 -0700, None <none@xxxxxxxxxxx> wrote:

Here is my situation:
A have a single DSL connection to the internet at my house. This
connection goes through a router, supplied by the ISP. Behind this
router is my LAN. I enjoy setting up various different servers (web,
news, irc, bbs, etc.), and would like to be able to access them from the
internet. With this many "test" servers running, however, there are many
potential security threats. I would like to create a separate "zone" on
my network, autonomous from the private LAN,

Generally referred to as "DMZ" when you search for firewall info

Here is my plan:
Configure the DSL router to foward the ports needed for the various
servers to a single computer. This computer acts as a firewall between
the two network zones.

It may not work very well, while I don't run DMZ at the moment, I
have prepared for that like this:

network topology
`````````````````
---------------- ------------ LAN
( ) Phone | | Machines
( Big Bad Internet )--------| ADSL Modem |
( ) Line | | 100-Base-T
---------------- ------------ Switch -----
| -------| |
Public IP | X_WORLD | -----
| | -----
------------- | --| |
| ppp0/eth2 | --- | -----
| | | \ |-- -----
X_LOCAL2 <-----|eth1 eth0|-----|/ /|-----| |
192.168.2.0/24 | | | \ |-- -----
100-Base-T | Firewall | --- | -----
(spare localnet) ------------- | --| |
| -----
| -----
-------| |
X_LOCAL -----
192.168.1.0/24

Firewall box: <http://bugsplatter.mine.nu/test/boxen/deltree/>

The firewall examines the destination port on
incoming packets, and based on that, DNAT's the address to the
appropriate physical server. (For example, redirect all packets destined
to port 80 to 10.0.0.2, and all packets destined for port 21 to 10.0.0.3).

Sure, but as someone else pointed out, you're doing a double NAT,
asking for trouble.

What I do is configure the ADSL modem to run in 'bridge' mode,
and run PPPoE on the firewall box --> I have complete control
over the link to Internet and what traffic hits localnet. (No
public access to localnet boxen, for example).

Hopefully, this will behave as expected.

It's fun stuff to play with. Take care not to be an unwitting
proxy though.

As a "networking neophyte", I would like to ask if this is a smart way
to do this. Is there an easier, or more efficient alternative? Any other
comments?

Couple years ago when I switched to ADSL I ran modem like you want
to, poking holes through the modem's firewall/NAT. As I climbed the
learning curve and gained confidence I switched modem to bridge mode
and not looked back.

See also: <http://bugsplatter.mine.nu/junkview/>

Grant.
--
Memory fault -- brain fried
.



Relevant Pages

  • Re: 3 LAN, 2 WAN - 2 LAN use 1 WAN, last LAN uses other WAN
    ... Internet over different paths after that. ... With a single LAN Router for all the segments, ... Then each "business" uses the Firewall they are supposed to use for the ...
    (microsoft.public.windows.server.networking)
  • Re: AdAware, SpyBot S &D, etc. + leave PC connected to Internet
    ... >It will be a while I get the router and do that. ... >> labelling on the box to be sure it has firewall features. ... name, like Disconnect from Internet, and click Finish. ... generally talking only about "critical patches" that affect security. ...
    (comp.security.firewalls)
  • Re: Makes no sense to me?
    ... I am not sure what is first here the servers or the routers to the internet? ... Router A starting or IP is ... Reconfigure the NAT Devices to use the same IP Range on the Internal LAN ...
    (microsoft.public.win2000.networking)
  • Re: Networking problems with router between 2 p.c.s
    ... >> router for internet access. ... >> disable the internet connection firewall in the LAN ... isn't suitable for use on a local area network. ...
    (microsoft.public.windowsxp.network_web)
  • Re: Low power mini-itx system for firewall
    ... and our servers tend to be SCSI). ... there are _firewall_ distributions that don't even need that much. ... get into our internet network, and allowing guest laptops to access only ...
    (comp.security.firewalls)