/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


    This is an idea I've been toying with for a while and I can't really
figure out what I want to do yet, but more important, if it can be
done.  Ideally, this is what the end result would look like (sorry if it
gets rewrapped):

=================>[ ROUTER ]
   ISP T1 w/        1|   |2
  3 diff. IP         |   |
    ranges           |   |port 2  ___________________
                     |   +-------[eth1           eth3]--->[ HUB 0 ]->
                     |           [      firewall     ]
                     +-----------[eth0  machine  eth2]--->[ HUB 1 ]->
                        port 1   [___________________]


    Here's what I'd like to do:

    Our router accepts different ranges of IPs, which is also what our
ISP has allocated to us.  I have three different subnets, two of them
coming on port 1, and the third one on port 2.  One has only a few IPs
in it, the other two have larger amounts.

    I'd like to have a firewall machine in there so that I can filter
out packets coming into (as well as going out of) our networks, and more
so, the specific PORT they're coming on.  Based on that data, they'll
get spit back out to the respective HUB, where there's a masq machine
waiting to receive/respond.

    What I'd like to ask is, whether this is even possible.  What are
the possible problems I will face with this setup.

    A few things we run in house are, 5 DNS' and 3 WWW servers which
also serve as FTP servers.  ONE of the IP ranges on port 1 has its
reverse lookup set at our ISP.  The other TWO ranges are managed in
house through Classless IN-ADDR.ARPA delegation (RFC2317 -
ftp://ftp.isi.edu/in-notes/bcp/bcp20.txt).  And I have some other
daemons running that need specific ports opened.

    So.  Is this possible?  If so, how would I go by setting up the
firewall machine.  Ideally I would like to have eth3 and eth4 be
192.168.x.x subnets, but they also have to be able to talk to each other
(meaning a machine sitting on one should be able to see a machine
sitting on the other).  Requests coming in on eth0 should be routed to
the respective machine on eth3/4 (depending on how I delegate it), and
the same goes for eth1.

    Also, does the firewall machine have to be something big and
powerful to be able to disassemble those packets and figure out what to
do with them?

    AMK4

--
W |
  |  Digital information lasts forever, or five years
  |   - whichever comes first.
  |____________________________________________________________________
  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  Ashley M. Kirchner <mailto:[EMAIL PROTECTED]>   .   303.442.6410 x130
  SysAdmin / Websmith                           .     800.441.3873 x130
  Photo Craft Laboratories, Inc.             .        eFax 248.671.0909
  http://www.pcraft.com                  .            3550 Arapahoe Ave
  .................. .  .  .     .                    Boulder, CO 80303

_______________________________________________
Masq maillist  -  Masq@indy.com
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to