LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 05-10-2007, 06:04 PM   #1
just_me_then
Member
 
Registered: Dec 2006
Posts: 59

Rep: Reputation: 15
Two cards, two ip/netmask ranges


Hello,

I have a server with two network cards. On will sit on one VLAN the other on another! Card 1 will have a public ip/netmask address and Card 2 and internal address/netmask.

I dont want anyone to be able to access the internal network through the server. The internal ip is only to be used for ssh access to the server. How would i set this up? If i just give the second network interface an ip address in a diffrent range the server dies! I asume i need to run some cleaver routing rule. Can anyone suggest what i need to be doing?

Thank You!
 
Old 05-10-2007, 06:57 PM   #2
jschiwal
LQ Guru
 
Registered: Aug 2001
Location: Fargo, ND
Distribution: SuSE AMD64
Posts: 15,733

Rep: Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682
You could as root:
echo 0 >/proc/sys/net/ipv4/ip_forward

Your distro may have a config entry in a gui program, such as YaST2 for example, or an entry in a file like /etc/sysconfig/networking where you can have it done when you boot. On a gui config program, it may be a checkbox to enable forwarding.

Also, make sure that the LAN IP address isn't used as the gateway on any of the machines on the lan.

If you have a firewall config program, only open the ssh port on the inside interface. This will use iptables rules, or you could edit them manually.
 
Old 05-11-2007, 06:36 AM   #3
kstan
Member
 
Registered: Sep 2004
Location: Malaysia, Johor
Distribution: Dual boot MacOS X/Ubuntu 9.10
Posts: 851

Rep: Reputation: 31
die? what u mean? which interface can't serve the user?
 
Old 05-11-2007, 07:13 AM   #4
jschiwal
LQ Guru
 
Registered: Aug 2001
Location: Fargo, ND
Distribution: SuSE AMD64
Posts: 15,733

Rep: Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682
The OP doesn't want traffic routed from eth1 (LAN) to eth0 (ethernet). (I'm making up device names because they weren't given.)
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
IP Ranges Cottsay Linux - Networking 3 03-03-2006 11:45 PM
Netmask? muppski Linux - Networking 5 01-30-2005 04:09 PM
netmask ray5_83 Linux - Networking 1 09-12-2004 11:20 AM
netmask spank Linux - Newbie 3 12-15-2003 09:12 AM
PPP netmask RHrulz Linux - Networking 3 02-04-2003 11:53 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 04:33 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration