How best to accomplish this

"Mike Scott" <[email protected]> Tue, 03 May 2011 09:18:34 -0700
Newsgroups gmane.org.user-groups.luni.tech
Message-ID <20110503091834.6095274834031e3691077dcdffae0724.3514ce2cc3.wbe@email00.secureserver.net>
Okay, here is the setup.

---------     ---------     -----------------
| LAN-B |-----| LAN-A |-----| Teh Internets |
---------     ---------     -----------------

I have a network, LAN-A for general-purpose use, including internet
access.
I want a more restricted LAN, LAN-B, that can also access the internet,
but is firewalled and appears to LAN-A and the web as a single NAT
address.  This is your basic home Broadband/DSL router stuff, but here's
where I am hitting a snag.

I want to make all IP addresses on LAN-A unreachable by LAN-B.
LAN-B can only access destinations *not* on the LAN-A subnet.
I am currently doing this with a PC running Coyote Linux and while it
works, I would like to use a small appliance rather than tie up a PC for
this purpose.

I have looked at a few routers and I think the last part is going to
require re-flash of the firmware with either dd-WRT or Open-WRT, which I
am not averse to doing.  Does anyone know if those distros will do this,
or if the Coyote Linux firewall has been ported to a commercial router
(i.e. low cost)?

- Mike Scott

-- 
Linux Users Of Northern Illinois (Chicago) - Technical Discussion 
http://luni.org/mailman/listinfo/luni