LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-28-2005, 07:26 PM   #1
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Posts: 2,190

Rep: Reputation: 60
routing correctly


Cable Modem
|
|
VOIPModem
|
|
Linux-Firewall/Router/SQUID proxy
|
|
Dlink wireless router-------------W2K server
|
|
Windows 2k wireless clients



I am redoing my network and I am adding another machine and it is going to be my firewall/router.

Cable Modem
|
|
VOIPModem
|
|
Linux-Firewall/Router- Server
|
|
Linux-SQUID proxy- Server
|
|
Dlink wireless router----------W2K Server
|
|
Windows 2k wireless clients

On the Squid Server, do I need to enable IP forwarding on that machine and then forward the packets to my Firewall server to be able to get my clients to the internet or do I only enable ip forwarding on just my Firewall?How do I route my ip packets to allow my clients to get to the internet. Before I had one machine doing it all. I have taken some of that payload off of the one server.

Last edited by metallica1973; 11-28-2005 at 07:32 PM.
 
Old 11-30-2005, 04:00 AM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
i would not use the proxy as a hop, instead you would filter outbound port 80 traffic on the firewall and redirect it to the server. At the same time though, a single SmoothWall or IPcop box can do all those functions in one unit, and it'd be no biggy if you made your own standard distro firewall do the proxying too. but ultimately, i would not add an extra hop, that's not fun.
 
Old 11-30-2005, 04:21 PM   #3
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Posts: 2,190

Original Poster
Rep: Reputation: 60
that is how I had it before. Isnt that too much for one machine to do, proxying and a firewalling? I wanted to lighten up the load on my main firewalling server. Will that extra hop slow things down or is it just more of a pain in the tookas?
 
Old 11-30-2005, 05:18 PM   #4
tkedwards
Senior Member
 
Registered: Aug 2004
Location: Munich, Germany
Distribution: Opensuse 11.2
Posts: 1,549

Rep: Reputation: 52
Any machine made in the last 5 years, maybe even before that, should have no trouble with doing both the firewalling and proxying so unless you've actually monitored the performance on that machine and seen that its overloaded I wouldn't bother.

If you do want to split it out then its pretty simple. The firewall/router does NAT (so yes you enable IP forwarding) and the Squid proxy machine has the Firewall/router machine as its default gateway. The Win2k clients can only then access the net through the Squid proxy - they can't connect directly to the net. If this was your intention in doing this you can easily achieve the same by turning off IP forwarding and NAT on the existing combined firewall/proxy setup.
 
Old 12-01-2005, 01:43 AM   #5
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
i wouldn't know if that machine is capable, as you didn't say how many clients there are... we're not psychic! like tkedwards said, it's probably safe to say yes it's fine, but IF you have +100 heavy net users behine it, then more likely not...
 
Old 12-01-2005, 02:52 PM   #6
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Posts: 2,190

Original Poster
Rep: Reputation: 60
many thanks! I had one more questions:

I upgraded my servers to kernel 2.6+ and I wanted to put my VOIP modem in its own DMZ off of my firewall. Can anyone give me some iptables rules to add to my firewall to allow udp ports 5060 UDP, 1020-1030 UDP, 13456-13463 to my DMZ where my VOIP modem is located. My DMZ will be on a 192.168.2.0 network. thanks

Last edited by metallica1973; 12-01-2005 at 02:56 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Not shutting down correctly BlueKnight Linux - General 2 08-31-2004 05:09 AM
real routing under nat routing nothingmuch Linux - Networking 4 10-27-2003 03:11 PM
did I do this correctly shanenin Linux - Software 1 09-24-2003 05:31 PM
am i doing this correctly? dunkyb Linux - Networking 19 02-07-2003 02:52 AM
Correctly installing CD RW... jambeck Linux - Hardware 14 11-09-2002 02:06 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:15 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration