LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-13-2009, 01:34 PM   #1
mxracer95
LQ Newbie
 
Registered: Jul 2009
Posts: 2

Rep: Reputation: 0
Shorewall, 2 NICs, Same Subnet


I've setup a small office network for a client. They lease space in a downtown building and are only given a single public IP address. The public IP goes into a Linxsys router, then to a switch connecting the LAN. I'm trying to setup a CentOS 5.3 server with 2 NICs, one NIC connects to the switch and the other to the DMZ port of the router. I want to configure Shorewall to allow all traffic originating from the LAN NIC, but filter traffic originating on the DMZ NIC. Both NIC's are on the same subnet which is my only option with this router.

I have a similar setup on my test network except that the LAN has a private IP and the WAN has a public IP. I copied the configs to my client's server but when I start Shorewall it blocks all traffic on both NIC's.

Is this because they are on the same subnet? That's the only difference between my working Shorewall config and this non-working config.

Is this just a bad idea all around?
 
Old 07-13-2009, 01:40 PM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
the difference between your lab and real scenarios is huge, as you are bridging at layer 2 instead of routing at layer 3. As such you would need to create a bridge interface between the two and use ebtables instead of iptables to do filtering.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Routing Between 2 NICs Application Compiled on 1 Subnet CanadianGoose Red Hat 1 04-20-2009 01:21 PM
two nics on one subnet on one machine mauricem Linux - Networking 2 04-27-2007 06:28 AM
two NICs on same subnet and ssh independently powah Linux - Networking 5 04-09-2007 12:56 PM
no outgoing ssh connection in subnet with shorewall/squid linux_marine Linux - Networking 2 11-21-2006 02:30 PM
2 nics on the same subnet mask wrexy Linux - Networking 6 10-11-2004 05:33 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:15 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration