LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 08-20-2008, 01:47 AM   #1
netboy_541
Member
 
Registered: Jul 2003
Location: Hamilton, OH
Distribution: Redhat 9, SuSE 10.1 & 10.2, Kubuntu
Posts: 173

Rep: Reputation: 30
Question a solution for two seperate lans to use one wan


Hello Everyone.

I'm trying to figure out a solution that will make my tenants lives a bit easier, and at the same time, I don't want to put my network out in the open.

Here's my "idea"...


I have one outbound internet connection.
I currently have it tied to my router, and about 10 devices are attached to it. (printers, servers, vmware servers, machines)
Since I'm such a nice guy, I am going to be sharing my internet with some of my tenants.
Of course, this will be filtered content, and they are aware that porn and the like is forbidden.

I do NOT want them to be able to connect to my lan infrastructure.
I have another AP, and want to have them connect to it. It's a router/firewall all in one. Plug it in, configure it, allow access, done.

I do not want them to be able to access MY lan at all, and would like a way to be able to throttle their bandwidth usage. The router I have does not allow for bandwidth restrictions.

I'm thinking I might be able to pull this off with some sort of a VMware solution, but I don't know.

I really really really need to be able to throttle the bandwidth coming from that network segment, but I'm not really sure what will do the job. I'm willing to purchase a hardware device, if it will let me throttle the wireless. I don't want to spend a bunch of money tho.

Hopefully this makes some sense....

I guess the easiest way to describe it is I'm building two separate networks, on two different subnets, but they use the same gateway to the internet. I just don't want anyone to be able and look at my side of the network.


Thanks for any ideas in advanced...
 
Old 08-20-2008, 02:00 AM   #2
rocket357
Member
 
Registered: Mar 2007
Location: 127.0.0.1
Distribution: OpenBSD-CURRENT
Posts: 485
Blog Entries: 187

Rep: Reputation: 74
Quote:
Originally Posted by netboy_541 View Post
need to be able to throttle the bandwidth coming from that network segment, <snip> I just don't want anyone to be able and look at my side of the network.
That could be done relatively easily with OpenBSD's pf.

http://cvs.openbsd.org/faq/pf/filter.html for restricting access to your lan
http://cvs.openbsd.org/faq/pf/queueing.html for bandwidth throttling
 
Old 08-20-2008, 02:06 AM   #3
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
You don't want them to be able to view your network because... they'll find your pr0n?

Ahh, but seriously... This is a very typical network deployment. All you need is a flexible firewall with 3 network interfaces. You plug one interface into your Internet-connected device (cable modem, DSL router, etc), and each of the other two interfaces plugs into a separate switch. You could attach a wireless AP to either switch and configure them with separate SSIDs, separate authentication keys, etc...

The key is that the firewall in the middle allows you to write rules such that no connections from interface B is allowed to go to interface C (assuming B is your guests, and C is your LAN). You can also configure separate QoS rules on each interface.

What allows you to do this? Well there are plenty of pre-built Linux and BSD OSs out there that are dedicated firewalls, or you could build your own solution from scratch by installing your favorite OS and writing the firewall rules by hand. The firewall OS could be installed "on bare metal", or on a VM, but either way you're going to want a box with 3 NICs in it. Most motherboards come with one built-in, so you'd install two more as expansion cards. Typically the built-in card has the lowest performance, so you'd use that for your Internet link since that's limited to the bandwidth of your cable/DSL connection any way. Use the two "good" cards for your LAN connections.
 
Old 08-20-2008, 05:59 AM   #4
netboy_541
Member
 
Registered: Jul 2003
Location: Hamilton, OH
Distribution: Redhat 9, SuSE 10.1 & 10.2, Kubuntu
Posts: 173

Original Poster
Rep: Reputation: 30
Well, I have business related stuff on my array, and I just don't want some jackass trying to sniff out my lan. I don't possess a single piece of porn on any of my machines. I happen to have a girlfriend. And a child. lol.


Anyway, I figured that would be the way to go about it. I have a stack of dual compaq netellegent lan cards, some old machines laying around too, so it sounds like i'll be pulling one of those out of the box and putting it to work.


Thanks guys!
 
Old 08-20-2008, 06:48 AM   #5
pinniped
Senior Member
 
Registered: May 2008
Location: planet earth
Distribution: Debian
Posts: 1,732

Rep: Reputation: 50
Have fun.

Did you check out the IPCop project to see if they have all the right toys for you?

http://www.ipcop.org/

They're the first firewalling distro that I'd heard of (back in 2001 I think) - of course it doesn't mean they are the first or even the best, but my buddies all swear by them.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
how to connect two lans? DrKranium Linux - Networking 3 08-27-2006 12:09 PM
FreeS/Wan Vs. OpenS/Wan Vs. StrongS/Wan bkankur Linux - Security 1 03-01-2005 09:27 AM
WAN : unable to ping to WAN ckl Linux - Networking 0 11-18-2004 01:56 AM
Routing through 2 LANs LeifWiderberg Linux - Networking 3 03-12-2004 11:00 AM
LANs andymay27 Linux - Networking 1 10-14-2001 02:14 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 03:51 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration