LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 11-28-2016, 05:16 AM   #1
LeoPap
Member
 
Registered: Jan 2013
Distribution: Centos
Posts: 99
Blog Entries: 1

Rep: Reputation: 10
Tricky DMZ Network with Routing needs (?)


Hello everyone,

I want to setup a DMZ on my existing network but let me explain first my network structure.

I have 20 PCS and 3 servers. All the PCS & Servers are in the same network (all of them have ip range 192.168.1....)

IP of Router: 192.168.1.1
IP of Main Server: 192.168.1.2
IP of Secondary Server: 192.168.1.6

What i want to do now is:

I want to add 10 PCS into the DMZ network and i also want these 10 PCS to be able to communicate with the router and servers.

NOTE: I am willing to launch another server in order to serve the DMZ purposes, but i am not capable to edit the existing settings of the servers and the router!

Any suggestions?
 
Old 11-28-2016, 06:19 AM   #2
smallpond
Senior Member
 
Registered: Feb 2011
Location: Massachusetts, USA
Distribution: Fedora
Posts: 4,140

Rep: Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263
If you want the added PCs to communicate with the others then why put them in a DMZ?
 
Old 11-28-2016, 06:20 AM   #3
LeoPap
Member
 
Registered: Jan 2013
Distribution: Centos
Posts: 99

Original Poster
Blog Entries: 1

Rep: Reputation: 10
Thank you for your reply!

I want to add them on a DMZ, because they will need to have access on the Internet (so far they didn't have access on the internet).
So in case one of the PCs catch a virus, i don't want to infect the rest of the network.
 
Old 11-29-2016, 03:28 AM   #4
Jjanel
Member
 
Registered: Jun 2016
Distribution: any&all, in VBox; Ol'UnixCLI; NO GUI resources
Posts: 999
Blog Entries: 12

Rep: Reputation: 364Reputation: 364Reputation: 364Reputation: 364
My guess is that you must[?] to put the 10PCs on a *different subnet* like 192.168.2.*
(at least for simplicity/clarity; I don't know whether you could do some tricky [=nasty!] 'mapping' to do all this on the ONE existing [sub]net! That would put 'evil' pkts on that LAN!)

New server would have three[!?] NICs: one to ..1.* LAN, one to new ..2.* LAN of 10PCs,
and one with a *publically-routeable* (not 192.168.*/10.*) ISP-provided address.

I don't know firewall! I'm guessing you have CentOS7 with firewalld. Best wishes! Let us know

** I welcome other LQ'ers feedback/corrections! (I hope this will prod things along here )

UPDATE edit: looks like *I* need to web-research like: network dmz diagram

Last edited by Jjanel; 12-02-2016 at 12:02 AM.
 
Old 12-01-2016, 06:35 AM   #5
smallpond
Senior Member
 
Registered: Feb 2011
Location: Massachusetts, USA
Distribution: Fedora
Posts: 4,140

Rep: Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263
No need for 3 nics. You can add the DMZ subnet on your internal nic and use iptables to route the traffic that you want.
 
  


Reply

Tags
dmz, linux, networking, routing



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Mutiple IPs and network cards routing (source policy routing?) shogun1234 Linux - Networking 1 01-17-2013 12:09 AM
Tricky Network Install mazebane Slackware 1 06-17-2005 06:24 AM
TRTP - Tricky Routing Task Problem tokehs Linux - Networking 7 08-27-2004 06:10 PM
tricky network RH9 install question! mindfestival Linux - Newbie 3 08-10-2004 09:51 PM
DMZ Routing jrmann1999 Linux - Networking 1 12-19-2002 12:26 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 06:44 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration