Re: How best to accomplish this

Julie Bell <[email protected]> Tue, 3 May 2011 13:23:06 -0700 (PDT)
Newsgroups gmane.org.user-groups.luni.tech
Message-ID <[email protected]>
While I am not a "true" network person. 

A possible hardware solution:

Network A 192.168.10.1 on one router  

Network B 192.168.2.0 on your main router hooked to internet
the Internet Port on Network A router is hooked to the Network B so that internet can be accessed, but they really 

can't see each other because of different subnets separated by the routers.




________________________________
From: Mike Scott <[email protected]>
To: [email protected]
Sent: Tuesday, May 3, 2011 11:18 AM
Subject: [LUNI] How best to accomplish this

Okay, here is the setup.

---------     ---------     -----------------
| LAN-B |-----| LAN-A |-----| Teh Internets |
---------     ---------     -----------------

I have a network, LAN-A for general-purpose use, including internet
access.
I want a more restricted LAN, LAN-B, that can also access the internet,
but is firewalled and appears to LAN-A and the web as a single NAT
address.  This is your basic home Broadband/DSL router stuff, but here's
where I am hitting a snag.

I want to make all IP addresses on LAN-A unreachable by LAN-B.
LAN-B can only access destinations *not* on the LAN-A subnet.
I am currently doing this with a PC running Coyote Linux and while it
works, I would like to use a small appliance rather than tie up a PC for
this purpose.

I have looked at a few routers and I think the last part is going to
require re-flash of the firmware with either dd-WRT or Open-WRT, which I
am not averse to doing.  Does anyone know if those distros will do this,
or if the Coyote Linux firewall has been ported to a commercial router
(i.e. low cost)?

- Mike Scott

-- 
Linux Users Of Northern Illinois (Chicago) - Technical Discussion 
http://luni.org/mailman/listinfo/luni

-- 
Linux Users Of Northern Illinois (Chicago) - Technical Discussion 
http://luni.org/mailman/listinfo/luni