Re: How best to accomplish this

Trev Peterson <[email protected]> Tue, 03 May 2011 22:32:15 -0500
Newsgroups gmane.org.user-groups.luni.tech
Organization Advanced Reality
Message-ID <[email protected]>
Sounds like you basically just need some firewall capabilities.  Next
questions are:

What performance is required and what/how many interfaces are needed (10
mbps, 10/100, giga)?
How reliable does it have to be?
How energy efficient?
What kind of management system (web-based, ssh, etc)?

Once you answer these you might find one of the following solutions will
work well for you:

linksys w/ dd-wrt (just disable the wireless):
http://cgi.ebay.com/Custom-Linksys-Wireless-Router-WRT54G-TM-WRT54GL-DD-WRT-/200600254931?pt=COMP_EN_Routers&hash=item2eb4b4f9d3

Leaf or Monowall on Alix:
http://pcengines.ch/alix.htm
http://leaf.sourceforge.net/bering-uclibc/
http://m0n0.ch/wall/

I've deployed over 30 leaf firewalls using Alix's predecessor (the wrap
pc) and they are a great option for a very stable, reliable,
power-saving firewall/router/vpn.  Hope this helps,


> From: Mike Scott <[email protected]>
> To: [email protected]
> Sent: Tuesday, May 3, 2011 11:18 AM
> Subject: [LUNI] How best to accomplish this
> 
>  Okay, here is the setup.
> 
> ---------    ---------    -----------------
> | LAN-B |-----| LAN-A |-----| Teh Internets |
> ---------    ---------    -----------------
> 
> I have a network, LAN-A for general-purpose use, including internet
> access.
> I want a more restricted LAN, LAN-B, that can also access the internet,
> but is firewalled and appears to LAN-A and the web as a single NAT
> address.  This is your basic home Broadband/DSL router stuff, but here's
> where I am hitting a snag.
> 
> I want to make all IP addresses on LAN-A unreachable by LAN-B.
> LAN-B can only access destinations *not* on the LAN-A subnet.
> I am currently doing this with a PC running Coyote Linux and while it
> works, I would like to use a small appliance rather than tie up a PC for
> this purpose.
> 
> I have looked at a few routers and I think the last part is going to
> require re-flash of the firmware with either dd-WRT or Open-WRT, which I
> am not averse to doing.  Does anyone know if those distros will do this,
> or if the Coyote Linux firewall has been ported to a commercial router
> (i.e. low cost)?
> 
> - Mike Scott

-- 
Trev Peterson
Advanced Reality
Email: [email protected]
Phone: +1 847 406 9018

-- 
Linux Users Of Northern Illinois (Chicago) - Technical Discussion 
http://luni.org/mailman/listinfo/luni