LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 09-28-2008, 04:44 AM   #1
mattjamal
LQ Newbie
 
Registered: Aug 2005
Location: uk
Posts: 17

Rep: Reputation: 0
how to configure firewall squid box


Hello everyone ,
this is my network scenerio:

CABLE MODEM ==> HUB == > {( eth1) Linux ROUTER (eth0) } ==> FW/SQUID ==> LAN Clients

I am very new to Linux Networking Operating System. I have setup my network as above, I configured my router machine to forward and allow incoming packet on ports (20,21,22,80 and 443).but my problem lies on the firewall/squid machine configuration. All I intend to have on the machine is to allow incoming and outgoing packets from the client machines on ports (20,21,22,80 and 443) using iptables. But I wondered how this could be done since I have One Ethernet card on it.
Please can anyone assist me in writing iptables and or to give me an assistance on how I could achieve this goal.

Thanks in advanced
Jamal
 
Old 09-28-2008, 07:23 PM   #2
salasi
Senior Member
 
Registered: Jul 2007
Location: Directly above centre of the earth, UK
Distribution: SuSE, plus some hopping
Posts: 4,070

Rep: Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897Reputation: 897
I'm not completely clear what you diagram shows; is it processes or computers? Maybe its flow of data. Assuming that your diagram does show computers/boxes/hardware, then, while the set up that you chosen may not be the most desirable (hey, but you didn't ask about that, right?) it looks as if it is relatively simple to get something that 'sort-of' works. If, on the other hand, you have serious concerns about the users of the lan clients as hackers or you want to ensure that your system is set up to minimise the pain of maintaining it in future, maybe you want to reconsider this, rather than presenting as a fait accompli.

It seems to me that you could achieve what you want by using iptables on the router box to only allow connections on eth0 from the FW/SQUID box. You could limit connections by mac address or IP address. I don't generally like this solution because it builds in a maintenance problem, but then its your mainteneance problem, not mine.

You should also note that you don't seem to be protecting your router box from the internet. Maybe this is something that you have just omitted from the diagram because it wasn't really relevant to this particular question.
 
Old 09-30-2008, 11:34 AM   #3
mattjamal
LQ Newbie
 
Registered: Aug 2005
Location: uk
Posts: 17

Original Poster
Rep: Reputation: 0
thanks for your reply. Yes my point is that I needed to protect my router from the internet but I dont know how.

CABLE MODEM ==> {( eth1) Linux ROUTER (eth0) } [ (eth0 )FW/SQUID (eth1)] ==> LAN Clients

I cannot do much on the router because it is a floppy firewalling. I run my firewall on a separate machine as drawn above.

My question is , what is the best practises to protect my router machine from the internet.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
hot to configure firewall squid box mattjamal Linux - Networking 1 09-28-2008 05:18 AM
Squid through Netgear VPN box tsaravan Linux - Networking 1 07-12-2007 05:34 AM
squid NTLM question box paul_mat Linux - Networking 0 02-09-2006 12:11 AM
dial-in server in a squid box mchitrakar Linux - Software 0 11-20-2004 11:21 AM
XP Box won't connect to internet thru RH9 Box (firewall/dhcpd), it can only ping fire Rhapsodic Linux - Networking 4 07-10-2004 03:02 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 11:25 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration