LinuxQuestions.org
Help answer threads with 0 replies.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 03-27-2010, 12:31 PM   #1
trist007
Senior Member
 
Registered: May 2008
Distribution: Slackware
Posts: 1,033

Rep: Reputation: 69
I'm interested in learning about implementing VLAN tagging into iptables...


My main goal is to build a firewall using VLAN tagging and iptables on a single NIC computer.

Here's my scenario. I have 4 computers. I have no router/firewall. I want the DSL connection coming from my ISP going into a 5 port switch. The 4 computers would then connect to the switch. Then I want to configure one computer with VLAN tagging and iptables to filter out the outside traffic and act as my firewall.

My plan was to configure two vlan interfaces on this one firewall computer. One for the in vlan interface(eth0.3) the other for out vlan interface(eth0.5). Then on iptables I can setup up eth0.3 to receive all outside traffic then redirect the legitimate traffic(based on my iptable rules) to the eth0.5, which would then pass on to the other 3 computers. Is iptables capable of directing traffic from eth0.3 to eth0.5. Then I would have to mark all the NICs on the 3 other computers to have VLAN eth0.5 tags?

Basically a firewall. Is this possible? I think my main problem is the switch that I have cannot be configured. Wouldn't I need to configure that switch to direct all outside traffic to eth0.3?

So yeah my guess is I need a managed switch with VLAN capacity.

Figured it out, assuming it's a managed switch, configure switch to send all inbound traffic to vlan tag 3. Then on that firewall computer configure the NIC to be vlan tag 3. I then write iptable rules on the firewall box to drop all illegitimate packets. Direct only legitimate traffic to vlan tag 5, which will be the same vlan tag on the NICs of the other 3 computers. Wouldn't this work? I just need a switch capable of 802.1Q.

Last edited by trist007; 03-27-2010 at 01:44 PM.
 
Old 03-28-2010, 06:46 AM   #2
OdinnBurkni
Member
 
Registered: Feb 2007
Location: Iceland
Distribution: Fedora 14, CentOS, FreeNAS
Posts: 127

Rep: Reputation: 20
VLAN tagging

I think you have to have a switch that supports VLAN's. So you would configure the DLS port for ID 5 untagged and the port connected to the firewall to both VLANs tagged and the other ports on ID 3 untagged. This is how I would do it. I think that's the only way unless you specify the VLAN on each pc. Another way (easier but doesn't include VLAN's) is to install another NIC in the firewall and connect that straight to the DSL.
OK. I didn't take a good enough look at your post. Sorry.
Yes, you're right I guess. Like I said you need to have the DSL port untagged but set to the right VLAN and same with the other PC's. But the port for the firewall needs to be tagged for both VLAN's.
Please keep us informed of your progress.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
802.1Q vlan tagging help td3201 Linux - Networking 1 09-23-2009 07:39 PM
VLAN Tagging Issue (Red Hat Ver 5) lensem Linux - Software 0 04-30-2009 09:22 AM
Catalyst 2924, DMZ and VLAN Tagging metallica1973 Linux - Networking 28 02-22-2008 08:14 AM
VLAN Tagging and Cisco 2924XL EN questions metallica1973 Linux - Networking 4 01-29-2008 01:08 PM
Iptables and implementing a policy sportsman667 Linux - Security 2 11-04-2007 06:30 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 07:55 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration