Re: How best to accomplish this
Trev Peterson <[email protected]> Tue, 03 May 2011 22:32:15 -0500
| Newsgroups | gmane.org.user-groups.luni.tech |
|---|---|
| Organization | Advanced Reality |
| Message-ID | <[email protected]> |
Sounds like you basically just need some firewall capabilities. Next questions are: What performance is required and what/how many interfaces are needed (10 mbps, 10/100, giga)? How reliable does it have to be? How energy efficient? What kind of management system (web-based, ssh, etc)? Once you answer these you might find one of the following solutions will work well for you: linksys w/ dd-wrt (just disable the wireless): http://cgi.ebay.com/Custom-Linksys-Wireless-Router-WRT54G-TM-WRT54GL-DD-WRT-/200600254931?pt=COMP_EN_Routers&hash=item2eb4b4f9d3 Leaf or Monowall on Alix: http://pcengines.ch/alix.htm http://leaf.sourceforge.net/bering-uclibc/ http://m0n0.ch/wall/ I've deployed over 30 leaf firewalls using Alix's predecessor (the wrap pc) and they are a great option for a very stable, reliable, power-saving firewall/router/vpn. Hope this helps, > From: Mike Scott <[email protected]> > To: [email protected] > Sent: Tuesday, May 3, 2011 11:18 AM > Subject: [LUNI] How best to accomplish this > > Okay, here is the setup. > > --------- --------- ----------------- > | LAN-B |-----| LAN-A |-----| Teh Internets | > --------- --------- ----------------- > > I have a network, LAN-A for general-purpose use, including internet > access. > I want a more restricted LAN, LAN-B, that can also access the internet, > but is firewalled and appears to LAN-A and the web as a single NAT > address. This is your basic home Broadband/DSL router stuff, but here's > where I am hitting a snag. > > I want to make all IP addresses on LAN-A unreachable by LAN-B. > LAN-B can only access destinations *not* on the LAN-A subnet. > I am currently doing this with a PC running Coyote Linux and while it > works, I would like to use a small appliance rather than tie up a PC for > this purpose. > > I have looked at a few routers and I think the last part is going to > require re-flash of the firmware with either dd-WRT or Open-WRT, which I > am not averse to doing. Does anyone know if those distros will do this, > or if the Coyote Linux firewall has been ported to a commercial router > (i.e. low cost)? > > - Mike Scott -- Trev Peterson Advanced Reality Email: [email protected] Phone: +1 847 406 9018 -- Linux Users Of Northern Illinois (Chicago) - Technical Discussion http://luni.org/mailman/listinfo/luni