Re: How best to accomplish this

Roman Kononov <[email protected]> Tue, 3 May 2011 21:02:51 -0500
Newsgroups gmane.org.user-groups.luni.tech
Message-ID <20110503210251.267ad497@snork>
On 2011-05-03, 09:18:34 -0700, "Mike Scott" <[email protected]> wrote:

> Okay, here is the setup.
> 
> ---------     ---------     -----------------
> | LAN-B |-----| LAN-A |-----| Teh Internets |
> ---------     ---------     -----------------
> 
> I have a network, LAN-A for general-purpose use, including internet
> access.
> I want a more restricted LAN, LAN-B, that can also access the internet,
> but is firewalled and appears to LAN-A and the web as a single NAT
> address.  This is your basic home Broadband/DSL router stuff, but here's
> where I am hitting a snag.
> 
> I want to make all IP addresses on LAN-A unreachable by LAN-B.
> LAN-B can only access destinations *not* on the LAN-A subnet.
> I am currently doing this with a PC running Coyote Linux and while it
> works, I would like to use a small appliance rather than tie up a PC for
> this purpose.

I think that any cheap router should do it. I have ASUS RT-N15, it
seems to be able to do it. Put it between LAN-A and LAN-B, LAN-A is its
WAN, LAN-B is its LAN. Turn off PPPoE, use a static IP on the WAN
interface. Turn on NAT ("router" mode), and the firewall. Set the
firewall to block all addresses belonging to LAN-A (do not block DNS,
NTP, ssh, etc.). The router can optionally provide a DHCP server for
LAN-B. It has a DNS relay as well. Wireless is optional.

Roman


-- 
Linux Users Of Northern Illinois (Chicago) - Technical Discussion 
http://luni.org/mailman/listinfo/luni