LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices

Reply
 
LinkBack Search this Thread
Old 06-03-2009, 04:00 PM   #1
scheidel21
Senior Member
 
Registered: Feb 2003
Location: CT
Distribution: Debian PPC/i386/AMD64 6/7, Vista, XP , WIN7, Server 03/08
Posts: 1,278

Rep: Reputation: 91
Setup a linux server between NAT firewall device and rest of network


Hi all,

Sorry if this has been asked before, but I am not even sure what to google for an answer so I thought I'd ask all of you.

The company I work for has been having some slow Internet issues, after much investigation ATT our T1 provider told us our line was saturated with traffic. so we started analyzing our internal traffic and according to Wireshark over an hour period we averaged only .391 MBits/s for traffic, but our Internet connection was still very slow during that time frame.

So let me give you an idea of our network

Code:
JuniperSSG140--->switch--->network
I modified this to get my wireshark info and it looks like this

Code:
JuniperSSG140--->Hub--|-->switch----->Network
                      |-->Linux Server running Wireshark
What I would like to do is place the Linux server at this point between the firewall and switched network so it looks like this

Code:
SSG140--->eth1--->eth0--->switch---->network
         (Linux Server)
This way I could run a realtime bandwidth monitor on Network traffic inbound and outbound from our internet connection.

My issue is that I am unsure how to configure it to bridge this way. I know I could use IP tables to NAT, but I want everything on the same subnet. and only want to put the server in-line. Currently eth0 is configured as 192.168.100.11 and eth1 is 192.168.100.6 the DHCP server tells everything the gateway is 192.168.100.1 I would like to not change that either.

Is there any way to bridge this? Would I set up a bridge interface br0 and add eth1 and eth2 to it and would that allow all traffic to pass through it looking for the gateway, do I need to use IPtables to route traffic from eth1-->eth0 and back?

I appreciate all your help thanks.

Alex
 
Old 06-03-2009, 04:27 PM   #2
billymayday
Guru
 
Registered: Mar 2006
Location: Sydney, Australia
Distribution: Fedora, CentOS, OpenSuse, Slack, Gentoo, Debian, Arch, PCBSD
Posts: 6,678

Rep: Reputation: 120Reputation: 120
I don't see why you need a bridge, you should be able to simply enable forwarding (echo "1" > /proc/sys/net/ipv4/ip_forward) and make sure that your iptables rules are allowing forwarding of packets (see FORWARD chain).
 
Old 06-03-2009, 04:41 PM   #3
ramram29
Member
 
Registered: Jul 2003
Location: Miami, Florida, USA
Distribution: Debian
Posts: 848
Blog Entries: 1

Rep: Reputation: 47
You should bridge two nic cards. One nic connected directly to the juniper (the outside link) and the other nic connected the swith (the inside link). Then run your wireshark that way.

Also, you may a computer with a bad network card. I would recommend to go through the process of elimination first to narrow down where the problem is. Start by using one computer then one by one, until you can detect where the symptom is coming from.
 
Old 06-03-2009, 07:49 PM   #4
scheidel21
Senior Member
 
Registered: Feb 2003
Location: CT
Distribution: Debian PPC/i386/AMD64 6/7, Vista, XP , WIN7, Server 03/08
Posts: 1,278

Original Poster
Rep: Reputation: 91
I appreciate the advice, I thought about a bad NC but nothing indicates that so far, and brnging one up at a time is easier said than done without interfering with operations. I also actually found iftop though, it seems to work great in promiscuous mode I probably will do bandwidth monitoring one day and sniff with wireshark once I get it in line hopefully I can sniff out the issue that way.
 
  


Reply

Tags
bandwidth, bridge, debian, lenny, monitoring, networking, subnet, wireshark


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Linux Firewall and Win 2003 server setup media-c Linux - Server 2 05-06-2009 05:22 AM
New to Linux, need to setup a firewall/gateway server. ChildOfThunder LinuxQuestions.org Member Intro 1 10-19-2007 08:19 AM
Setting up firewall / nat server da644 Linux - Networking 1 08-02-2005 08:22 PM
setting up a linux server + firewall + nat ddaas Linux - Security 7 10-14-2004 06:42 PM
help with client side NFS-firewall setup and server side NIS-firewall setup niverson Linux - Networking 3 02-02-2004 08:52 AM


All times are GMT -5. The time now is 08:11 AM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration