Re: ipfw/natd/3 nic

From: Barney Wolff (barney_at_databus.com)
Date: 12/23/03

  • Next message: Darcy Buskermolen: "Re: ipfw/natd/3 nic"
    Date: Tue, 23 Dec 2003 11:23:23 -0500
    To: Peter Serwe <peter@easytree.net>
    
    

    On Tue, Dec 23, 2003 at 08:23:00AM -0500, Peter Serwe wrote:
    >
    > I have 2 internal networks that I'll term
    > private_private (192.168.1.0/24)
    > and public_private (192.168.2.0/24).
    >
    > I have one public ip address.
    >
    > I need both networks to be able to surf,
    > but I _never_ want ANY traffic to be able
    > to go in between except from someone having
    > direct access to the router. The router shouldn't
    > be passing any traffic in between private networks.

    I don't think you need(ed) two public addresses to accomplish what
    you want. The ipfw divert rule can have "via <external-nic>" to
    apply only to packets to/from the Internet, and you can have deny
    rules for packets flowing between your two internal nets. I don't
    see a need to run two natd's here.

    -- 
    Barney Wolff         http://www.databus.com/bwresume.pdf
    I'm available by contract or FT, in the NYC metro area or via the 'Net.
    _______________________________________________
    freebsd-net@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-net
    To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"
    

  • Next message: Darcy Buskermolen: "Re: ipfw/natd/3 nic"

    Relevant Pages

    • Re: tpg cancel attack
      ... Internet connections to move traffic. ... common set of communications protocols. ... The vast collection of inter-connected networks across the world that ... A worldwide network of computer networks. ...
      (talk.politics.guns)
    • Re: Steve our posts have been deleted!!!!!
      ... That's due to the amount of bandwidth used for streaming! ... internet to serve 10-million listeners; there is simply no way the ... actually where in the coverage-zone of their terrestial networks. ... Of course, when you are talking about non-linear broadcasting, that's ...
      (alt.radio.digital)
    • RE: GPO that forces users to use a proxy server.
      ... as I would think home networks are not proxied and filtered. ... GPO that forces users to use a proxy server. ... proxy sever for there internet access in the company, ...
      (Focus-Microsoft)
    • Should Obama Control the Internet?
      ... Do you know about the Rockefeller Snowe job? ... A new bill would give the President emergency authority to halt web ... Should President Obama have the power to shut down domestic Internet ... concerning networks without regard to any provision of law, ...
      (alt.gathering.rainbow)
    • RE: How hackers cause damage...
      ... PBX and phone systems are PUBLIC networks. ... than list the internet as an agreed path. ... The cost of security is inverse ... Network Vulnerability Assessment project here in Australia and you may ...
      (Security-Basics)