LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 11-11-2008, 10:43 AM   #1
vortmax
Member
 
Registered: Nov 2005
Posts: 91

Rep: Reputation: 17
IPtables + snort = homebrew internet gateway


I'm attempting to build an IPS internet gateway by using snort-inline for the IPS and iptables to handle the routing, but I'm having issues getting iptables to work.

I have an MPLS network that is supplying internet out to apartment complexes. This firewall is sit at the head of this network to fish out attacks. I still need to treat this network as insecure. I have 3 nics on the server I am using. One will be the WAN side of the network, the second will be the LAN side, and the third will be a management IP that is on my corporate local network (secured).

What I need to do is to have all traffic entering the LAN nic be directed to the queue for snort to crunch on before being directed out the WAN. Same thing for the WAN to LAN. I need the third NIC to allow complete access from a third network, but never allow any host on the LAN or WAN side onto the private network. Does that make sense?

How do I go about doing this? Do I give the LAN and WAN nics their appropriate IP's, then do some routing with iptables, or do I need to configure a bridge?
 
Old 11-12-2008, 02:56 AM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
Well in general that's all fine. no bridging though, just route through in all three directions and firewall off your management interface with iptables. I mean, you *could* bridge if you want to be transparent, but i'd not see any real reason to do that unless youre immediate routing in neighboring lan segments isn't able to be correctly configure for an additional layer 3 hop. Are you having specific issues with this, or just running it past others?
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
iptables rules for an ubuntu gateway (filtering connections to and from Internet) Zingaro2002 Linux - Networking 4 05-06-2007 02:01 AM
installing snort on high traffic gateway bog it down? kcorupe Linux - Server 2 04-06-2007 08:02 AM
problem setting up internet gateway using iptables sweemeng Linux - Networking 2 07-12-2006 01:59 PM
Internet gateway on FC3 -Do i need iptables ? dannie Linux - Networking 4 12-08-2004 02:47 PM
internet gateway problems (iptables configuration) woranl Linux - Networking 11 08-27-2003 11:41 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 12:18 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration