LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 11-23-2005, 06:34 AM   #1
Samhein
LQ Newbie
 
Registered: Nov 2005
Posts: 13

Rep: Reputation: 0
Configuring SUSE 10 with 2 NICs as gateway/DHCP


Greetings,

We have an open network here at work (no need for login). Recent abuses led us to the decision of installing linux as a server/firewall. On a first stage, however, we're only setting it as a monitoring post between the router and the lan, in order to monitor all internet access without interfering. As such, the pc has 2 NICs, and the firewall mustn't block anything, except what deals directly with the pc. So I want the router to connect directly to one NIC, and the other NIC to connect directly to the rest of the LAN. This has to be done transparently, though.
The router is 10.0.0.1, it's DHCP is set for 10.x.x.x as of now. The linux PC (DSF-LS) is 10.0.0.250, and I've set up DHCP for 2nd NIC 10.0.0.3-10.0.0.249.
Now, I don't know how to define things so DSF-LS won't start blocking things for the net. The point now is to allow everything, even dangerous content to the computers. Of course, I don't want DSF-LS hacked, or attacked.
It's been a long time since I last used linux, and I'm a bit behind the times. Is there a simple way to set it as a transparent gateway? All I want for now is to monitor every single packet through the net (I'm using ethereal. If there's a better one, advices are always welcome!).
The first and 2nd NICs are configured in the same way (ip 10.0.0.250, default gateway 10.0.0.1, DNS are ISP's).

Any ideas would be helpful. Not sure if my post is clear enough. Any subsequent doubts, please post and I'll clear them as possible.
 
Old 11-23-2005, 01:51 PM   #2
mikedeatworld
Member
 
Registered: Nov 2003
Location: Farmington Michigan
Distribution: UBUNTU - Slackware - SuSE 9.1 - Knoppix - Fedora
Posts: 828

Rep: Reputation: 30
1. Is DHCP working?
2. What do you mean by "The point now is to allow everything, even dangerous content to the computers."
3. The firewall will not filter "content" like say a web filtering software like websense
4. Configure IPTABLES to open/close any TCP/UDP ports needed.
5. If you need a GUI to open/close firewalls try www.webmin.com
6. Ethreal is good, but check out www.nagios.com


Last edited by mikedeatworld; 11-23-2005 at 01:53 PM.
 
Old 11-24-2005, 08:42 AM   #3
Samhein
LQ Newbie
 
Registered: Nov 2005
Posts: 13

Original Poster
Rep: Reputation: 0
Quote:
Originally posted by mikedeatworld
1. Is DHCP working?
2. What do you mean by "The point now is to allow everything, even dangerous content to the computers."
3. The firewall will not filter "content" like say a web filtering software like websense
4. Configure IPTABLES to open/close any TCP/UDP ports needed.
5. If you need a GUI to open/close firewalls try www.webmin.com
6. Ethreal is good, but check out www.nagios.com
1. Not sure if it is, as I haven't placed it between the router and LAN yet. I am just configuring it. However, the pc stopped accessing the internet once I added the second NIC. How do I set up one NIC for communication with the router only, and the other for LAN only?
2. Right now, we want to monitor the net as if the linux pc wasn't there. So everything that was allowed before must still be allowed now, so we can see exactly what it is, and who is using it.
3. I am aware of that. I would start searching for a good program for that, once I got the pc monitoring the net. If you have some advices about that, I would also appreciate it.
4. As I said in 2, I want the firewall to block only connection that relate to the linux pc, and let everything else go by, even if it's malware. Once we set the pc to block, I can manage the firewall (hopefully!
5. I don't think the problem is with the firewall itself. But btw, our main goal, besides some content blocking, is to block programs like Kazaa and Imesh, which change ports dinamically, and will even use port 80 if everything else is blocked. I know that an IPTABLES firewall can block that through the packet header. I was thinking of using SUSE Firewall, since it already comes with the OS, but do you have any other advices as well?
6. Thanks, I will check that once I get the pc working.

My main goal for now is for the linux pc to monitor the net as if it wasn't there. That is, the router and other pcs don't notice it is there. I want a transparent gateway, if possible.

Thanks for the reply.
 
Old 11-24-2005, 11:05 AM   #4
Samhein
LQ Newbie
 
Registered: Nov 2005
Posts: 13

Original Poster
Rep: Reputation: 0
Ok, I finally managed to get it working. This article helped me a lot: http://www.novell.com/coolsolutions/feature/16022.html

As for the webcontent and firewall advices, I would still like those.
Thanks for all the replies!

EDIT: I'm not sure if the firewall is now blocking dangerous packets to go through. But on second thought, we don't want to go on a crusade to catch abusers. We're happy if we just stop the abuse. So I'll start configuring the firewall soon.

Last edited by Samhein; 11-24-2005 at 11:33 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Linux Gateway with 3 NICs pin_bk Linux - Networking 16 03-27-2005 09:57 AM
Linux Gateway+Two NICS+Router+HOWTO pin_bk Linux - Networking 11 09-07-2004 12:29 PM
can't get nics working, on gateway evilchild Slackware 3 03-28-2004 07:18 PM
How do I connect dual nics in firewall to the gateway? scoobadiver Linux - Newbie 3 01-12-2004 05:03 PM
Setting up Redhat squid gateway with dual NICs wrathyimp Linux - Networking 13 06-12-2003 11:54 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 02:18 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration