LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-23-2010, 09:40 PM   #1
richinsc
Member
 
Registered: Mar 2007
Location: Utah
Distribution: Ubuntu Linux (20.04)
Posts: 224

Rep: Reputation: 32
Transparent Firewall with squid/dansguardian


I am posting this in security because it is firewall related. I am looking to redesign my network which I'll get into bellow but basically i am looking to setup an transparent/bridged firewall with squid and dansguardian. However, I want to require LDAP authentication to access internet. You'll understand why from diagram below.

My question is, since bridged firewalls operate at layer 2 and have no/require no IP address, can you access higher layered apps with them? Example would be to have the proxy authenticate to LDAP system to check for valid user and valid net permissions, server has to somehow send a reply back, so without an IP, this can't happen right.

Below are two designs I am looking into implementing. Everything Internally will be Authenticated against LDAP with a small possibility of some public servers using LDAP too, but in my way of thinking anything using LDAP would should be behind the router on private link. FYI, the PROXY and the Linux Router would be two physically separate systems.

So I guess my second question would be, can systems outside private network access limited internal services securely and be restricted at the same time?

I think I have everything I needed to ask but if I think of something else related to this I'll post in reply if it concerns app/firewall question.

Code:
Option 1:
                        (TRANSPARENT)
------------            -------------
| CBL MODM | ---------> | PROXY/FW  |
------------            -------------
                              |
                              |{PUBLIC)
                              |
   ----------            --------------           ---------
   |  DMZ    |<----------| LNX ROUTER |---------> | WI-FI |
   ----------            | W/FIREWALL |           ---------
                         --------------
                                |
                                |(PRIVATE)
   ---------------              |                ---------------
   | LDAP SERVER |<----------------------------> | VPN / WikId |
   --------------                                ---------------


Option 2:

                        (TRANSPARENT)
------------            -------------
| CBL MODM | ---------> | PROXY/FW  |
------------            -------------
                              |
                              |{PUBLIC)
                              |
   ----------            --------------           ---------
   | SERVER |<---------- |  SWITCH    |---------> | SERVER |
   ----------            --------------           ---------
                               |
                               |
                         --------------           ---------
                         | LNX ROUTER |---------> | WI-FI |
                         | W/FIREWALL |           ---------
                         --------------
                                |
                                |(PRIVATE)
   ---------------              |                ---------------
   | LDAP SERVER |<----------------------------> | VPN / WikId |
   --------------                                ---------------

Last edited by richinsc; 02-23-2010 at 09:42 PM.
 
Old 03-01-2010, 03:13 AM   #2
OdinnBurkni
Member
 
Registered: Feb 2007
Location: Iceland
Distribution: Fedora 14, CentOS, FreeNAS
Posts: 127

Rep: Reputation: 20
Transparent firewall/proxy

Hi.
I'm not sure if this will answer your question and I don't know how experienced user you are. I've tried ClearOS and I like it in many ways. It supports many nics and I would rather go for one box if possible. In ClearOS you have web based interface to config things but you can also do it in CLI. It's based on CentOS if I remember it right. If you're more experienced user you could also just use clean Linux installation, CentOS or Ubuntu or whatever you prefer, and use f.ex. iptables to handle the security and determine who's allowed to go where...

I hope it helps...
 
Old 03-01-2010, 03:47 AM   #3
Winanjaya
Member
 
Registered: Sep 2003
Posts: 239

Rep: Reputation: 32
Mine looks simple: ;< )

PIX Firewall -> Internet Router -> Squid (Transparent Proxy) + IPTables, Internal DNS, Mail, LDAP ---> Users

Squid Gateway: to PIX Firewall

Users Gateway: to Squid
User DNS: to Internal DNS

I also do NAT for some virtual servers (ie. www, POP3, SMTP Auth)


Thanks & Regards
Winanjaya
 
Old 03-01-2010, 03:48 AM   #4
Winanjaya
Member
 
Registered: Sep 2003
Posts: 239

Rep: Reputation: 32
I also had WIFI and its gateway to Squid and also had DHCPD server (gateway also to Squid)
 
Old 03-01-2010, 03:59 AM   #5
OdinnBurkni
Member
 
Registered: Feb 2007
Location: Iceland
Distribution: Fedora 14, CentOS, FreeNAS
Posts: 127

Rep: Reputation: 20
Firewall

I like the way Winanjaya does it. It's fairly easy to implement. Regarding the iptables, I use a script for that so it's easier (well at least it is for me) to configure. I can dig up a template of that script if you're interested, or you might be able to find it in some of my posts here on LQ, I've shared once or twice.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Transparent squid with dansguardian , parmeshwary2k Linux - Networking 29 05-04-2010 12:35 PM
Transparent Proxy (squid + Dansguardian) with one NIC azrim Linux - Server 4 04-28-2010 08:42 AM
IPTABLES, SQUID, DANSGUARDIAN and Transparent Proxy metallica1973 Linux - Networking 18 09-03-2007 07:17 PM
Need secure OS for squid+dansguardian firewall drokmed Linux - Security 6 06-23-2006 03:43 PM
squid (Transparent proxy) & Dansguardian metallica1973 Linux - Security 8 12-15-2005 07:52 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:41 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration