LinuxQuestions.org
Help answer threads with 0 replies.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 09-18-2008, 06:56 PM   #1
init.p
LQ Newbie
 
Registered: Sep 2008
Posts: 1

Rep: Reputation: 0
Question Software Gateway/Firewall


I have setup a test lab at work to implement and play around with a few servers. All servers in the test lab are located in their own non-NAT subnet that has access to all LAN subnets, but any WAN/Internet traffic is blocked by the routers.

However, for some services I need outside access. And in some cases, I want to completely block all traffic to the internal LAN. Instead of asking the networking team to just open up the subnet and configuring firewalls on all servers, I thought it would be interesting (and more efficient) to set up a custom gateway/firewall for the entire subnet.

I started configuring the gateway with two NICs - eth0 is for the internal subnet, eth1 is on a subnet that's open to the world. Ok, and here is where I need help. How to I accomplish the rest? Packet forwarding via IPtables, like a simple -A FORWARD -i eth0 -o eth1 -j ACCEPT? Do I need to put both NICs into promiscuous mode?

eth0 is xxx.xxx.71.10, eth1 is xxx.xxx.65.10

The plan is to configure all network clients with xxx.xxx.71.10 as their gateway, so I can open/close the firewall on the gateway for certain services (for updates, access for test clients in the 65 subnets, etc.)

Addendum: Right now, I have set up IP forwarding via IP tables, enabled ip_forward via syctl and some things seems to work, but not entirely. Outgoing traffic works great, but only on the LAN (internal network, 65 and beyond), but that's it, no access to the outside world. What did I miss?

Thanks for your help,
Pat

Last edited by init.p; 09-18-2008 at 07:06 PM.
 
Old 09-27-2008, 05:32 AM   #2
racracracrac
Member
 
Registered: Sep 2008
Posts: 44

Rep: Reputation: 15
Your post is a little rambling, but if I understand your question, here is the answer:

The traffic on the inside of your firewall knows how to get out because you setup a default gateway. The traffic from your router knows how to get out because you setup a router. But the responding traffic doesn't know how to get back because the hosts on those networks don't have routes to get back. You could either create routes on ALL of those systems, or here is the simple answer.

Enable nat on your outside interface. Then all traffic will appear (to the outside hosts) to come from the external interface of your firewall.

Last edited by david_ross; 10-09-2008 at 12:03 PM. Reason: Removed spam
 
Old 10-09-2008, 12:04 PM   #3
david_ross
Moderator
 
Registered: Mar 2003
Location: Scotland
Distribution: Slackware, RedHat, Debian
Posts: 12,047

Rep: Reputation: 79
racracracrac, please don't add spam links to your posts. If you would like to link to your own site this can be done in your profile.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
router billion 5102 has firewall and software firewall tests aus9 Linux - Security 6 12-31-2006 10:09 PM
Using Linux as a firewall/gateway Dovid Linux - Networking 4 04-21-2005 09:13 PM
Building a firewall/gateway Mogwa_ Linux - Networking 1 07-13-2004 06:42 AM
Firewall\Gateway Script ASP Linux - Security 5 09-22-2003 10:15 PM
RedHat 7.3 as Gateway/Firewall NegativeZERO Linux - Networking 6 12-02-2002 12:57 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 01:52 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration