Re: How best to accomplish this

"Mike Scott" <[email protected]> Tue, 03 May 2011 13:53:29 -0700
Newsgroups gmane.org.user-groups.luni.tech
Message-ID <20110503135329.6095274834031e3691077dcdffae0724.a30a1587a8.wbe@email00.secureserver.net>
Thanks Julie, 
Unfortunately, I don't have access to the border router.  It's managed
by our WAN group and I am just a local sysadmin and there's a butt-load
of paperwork, justification, testing required for any change request.

This was set up to allow computers running MS-Windows and Office to be
temporarily hung on the internet to activate.  I am currently looking to
free up some rack space and get rid of the old tower PC currently
performing this task.

I heard back from a from coworker that dd-wrt has this capability, so I
may get hold of a cheap broadband device and test it out.  I'll let you
all know how it works.

- Mike Scott


-------- Original Message --------
Subject: Re: [LUNI] How best to accomplish this
From: Julie Bell <[email protected]>
Date: Tue, May 03, 2011 3:23 pm
To: "Linux Users Of Northern Illinois (Chicago) - Technical Discussion"
<[email protected]>

While I am not a "true" network person. 

A possible hardware solution:


Network A 192.168.10.1 on one router  

Network B 192.168.2.0 on your main router hooked to internet
the Internet Port on Network A router is hooked to the Network B so that
internet can be accessed, but they really 

can't see each other because of different subnets separated by the
routers.






From: Mike Scott <[email protected]>
To: [email protected]
Sent: Tuesday, May 3, 2011 11:18 AM
Subject: [LUNI] How best to accomplish this

 Okay, here is the setup.

---------    ---------    -----------------
| LAN-B |-----| LAN-A |-----| Teh Internets |
---------    ---------    -----------------

I have a network, LAN-A for general-purpose use, including internet
access.
I want a more restricted LAN, LAN-B, that can also access the internet,
but is firewalled and appears to LAN-A and the web as a single NAT
address.  This is your basic home Broadband/DSL router stuff, but here's
where I am hitting a snag.

I want to make all IP addresses on LAN-A unreachable by LAN-B.
LAN-B can only access destinations *not* on the LAN-A subnet.
I am currently doing this with a PC running Coyote Linux and while it
works, I would like to use a small appliance rather than tie up a PC for
this purpose.

I have looked at a few routers and I think the last part is going to
require re-flash of the firmware with either dd-WRT or Open-WRT, which I
am not averse to doing.  Does anyone know if those distros will do this,
or if the Coyote Linux firewall has been ported to a commercial router
(i.e. low cost)?

- Mike Scott

-- 
Linux Users Of Northern Illinois (Chicago) - Technical Discussion 
http://luni.org/mailman/listinfo/luni





-- 
Linux Users Of Northern Illinois (Chicago) - Technical Discussion 
http://luni.org/mailman/listinfo/luni

-- 
Linux Users Of Northern Illinois (Chicago) - Technical Discussion 
http://luni.org/mailman/listinfo/luni