Re: for each box on a very small lan: route, multi subnets, ip alias



Alan_C <mtbr0228AT@xxxxxxxxxxxxxxxx> writes:
<snip>
----*******--key----*******-------
How to add routes or what would the routes look like? Keep the currently
existing default route? (the internet gateway 192.168.1.254)

None of these 3 Linux desktops would be a router, none would forward traffic
beyond itself.

But (this I need help on, I'm confused as to how to get this) each box here
needs it's own ability to know which subnet to use for which sort of traffic.
whether the traffic be internet or lan traffic.
----*******--key----*******-------

I think I just answered part of my own question. I think I keep the
default gateway route to internet gateway.

Of course I add another route to the 2nd subnet, lan subnet (still not
sure what to add here).

lan traffic would find the other box because traffic from one lan box
to another lan box is traffic that was or is pointed from box number
one to box number two on the lan (destination ip and both box using
same subnet)

http (web browser, etc.) would most likely (hopefully) use the default
gateway route.

I then merely firewall whichever interface is the internet interface.

I don't know if it matters which interface is used for what. That is,
which subnet the virtual interface gets assigned to and which subnet the
real interface gets assigned to.

Any other concerns? I may not be yet sufficiently experienced so as to
engineer. Yes I know there's other ways (use 1 Linux firewall/router
between lan and internet).

But this is such a small lan with just 3 Linux desktops. So, what I've
proposed appears reasonable (from my limited experience viewpoint)

Thanks.

--
Alan.
.



Relevant Pages

  • Re: Routing based on packet source?
    ... There is no way to route traffic differently based on where it came ... > RAS and IIS. ... > LAN internet access was easy because there was only 1 WAN nic (the ... I want keep my LAN surfers *off* the T1 ...
    (microsoft.public.win2000.ras_routing)
  • Re: Q: How to do the DMZ routing?
    ... LAN ... a static route in FW.eth2 to reach LAN/xx ... all incoming traffic from Internet to LAN is forbidden (except if ... the selected incoming traffic from Internet to DMZ has to be allowed ...
    (comp.security.firewalls)
  • Re: 2 nics - Routing
    ... Assuming NIC 1 is on 10.0.2.0/24 LAN, the route for that LAN would be ... and network routes for both LANs)? ... For either of your private networks to get to the internet, ...
    (comp.os.linux.misc)
  • Re: Win2k3 R2 does not route to virtual guests
    ... We use an ISA as a combined firewall/router in another setup so I'm not ... it doesn't route between the External and any other ... The device called Host will become the LAN Router in this topology. ... Internet Device happens to be ISA. ...
    (microsoft.public.win2000.networking)
  • Re: How to Stop bypassing Proxy server?
    ... You could try threaten to break the legs of the users that bypass the proxy, ... normally the internet gateway is on a sperate Lan and the ...
    (comp.security.firewalls)