LinuxQuestions.org
Review your favorite Linux distribution.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices

Reply
 
LinkBack Search this Thread
Old 06-30-2006, 11:44 AM   #1
threegig
LQ Newbie
 
Registered: Jun 2005
Posts: 16

Rep: Reputation: 0
Network on 2 Ranges


Hi Everyone,

I am re organising my home network and wanted to seperate the wireless clients from my internal wired network. My slackbox will have 2 nics and will act as a small fileserver for a wireless client.

Say I gave one of the nics in the slack box a ip of
192.168.1.1 For the wifi side
and
192.168.0.1 For the internal side would this improve security?
And my other major question is the 2 ip's above have the same subnet is there any problem or disadvantage with using 2 different subnets. For instance-
wifi side - 192.168.1.1
internal side - 10.0.0.1
How is this compared to the same subnet scenario?

Here is a diagram of my setup

Code:
[wifi.1]  ----|----   [wifi.2]
              |
              |
       [Billion 7402VGP]
              |
              |
          [Slackware] 2 x nics
              |
              | 
           [switch]
  |-----------|-----------|
[NIX]	-   [XP2]   -   [XP3]

Thankyou very much
 
Old 06-30-2006, 12:53 PM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 39,835

Rep: Reputation: 1118Reputation: 1118Reputation: 1118Reputation: 1118Reputation: 1118Reputation: 1118Reputation: 1118Reputation: 1118Reputation: 1118
keeping your wifi clients in a dmz is a reasonable thing to be looking to do, certainly, but you've not mentioned a nomber oft higns like where your internet connection comes into it and such. there is only more security if you are enabling a firewall between the two subnets and not just directly routing between the two.

for your second issue i think you believe there is some form of connection between 192.168.0.0/24 and 192.168.1.0/24 as opposed to 10.0.0.0/24? no there is nothign in common, they are *not* in the same subnet at all, you've got your terminology mixed up there.
 
Old 06-30-2006, 02:18 PM   #3
ramram29
Member
 
Registered: Jul 2003
Location: Miami, Florida, USA
Distribution: Debian
Posts: 842
Blog Entries: 1

Rep: Reputation: 44
You can do that. You can also use just one NIC and assign mulitple IP addresses to it; to the same NIC card.
 
Old 06-30-2006, 02:25 PM   #4
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 39,835

Rep: Reputation: 1118Reputation: 1118Reputation: 1118Reputation: 1118Reputation: 1118Reputation: 1118Reputation: 1118Reputation: 1118Reputation: 1118
putting multiple subnets on a single nic without formal vlan's is a really really bad idea. often works, but only from dumb luck, and creates massive security issues.
 
Old 06-30-2006, 05:03 PM   #5
threegig
LQ Newbie
 
Registered: Jun 2005
Posts: 16

Original Poster
Rep: Reputation: 0
Thanks Guys for your replys.

acid_kewpie - Thanks. The billion will pass out the net connection. So I am hoping that my internal pc's can use the billion ip as the gateway and that will be fine.
Also on the slack box I am going to set up a firewall between the 2 nics. Letting web pages out but nothing in. Will this be ok?
And with my question sorry I meant different subnet mask like this -
192.168.1.1
192.168.0.1
Subnet Mask - 255.255.255.0

or the other way I though

192.168.1.1
10.0.0.1
2 Subnet Masks - Sorry got mixed.

Is having 2 seperate subnet masks a issue?

Thanks for you expertese.
 
Old 07-01-2006, 03:51 AM   #6
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 39,835

Rep: Reputation: 1118Reputation: 1118Reputation: 1118Reputation: 1118Reputation: 1118Reputation: 1118Reputation: 1118Reputation: 1118Reputation: 1118
you mean you'd have 10.0.0.0/255.0.0.0 instead of 10.0.0.0/255.255.255.0 ? if so that is still not a concern, but i'd always suggest using a 24 bit mask if you don't need that much local ip space.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
IP Ranges Cottsay Linux - Networking 3 03-03-2006 11:45 PM
display out of ranges yenonn Fedora 3 01-19-2005 12:54 AM
Ranges in OpenOffice CRego3D Linux - Software 0 06-19-2003 12:00 PM
C number ranges nocturnal Programming 7 05-16-2003 05:24 PM
network address ranges WeNdeL Linux - Networking 4 03-12-2003 10:56 AM


All times are GMT -5. The time now is 08:58 PM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration