Linux Netfilter discussions
 help / color / mirror / Atom feed
* RE: Advice on network config (unix - linux and windows - mac)
  2002-10-14 12:58 Advice on network config (unix - linux and windows - mac) David Bourgeois
@ 2000-10-16 22:20 ` Rowan Reid
  0 siblings, 0 replies; 4+ messages in thread
From: Rowan Reid @ 2000-10-16 22:20 UTC (permalink / raw)
  To: 'David Bourgeois', netfilter






 INTERNET<--------------->FIREWALL<--------nated systems on private net
					^
					|_______ DMZ

Firewall with 3 nic cards. Setup with a iptables filtering firewall that
nats all outgoing requests from your private network. And
filter/forwards incoming traffic to your DMZ. All attempts to connect to
your firewall are dropped and and logged unless they are established
connections (returning nat) or are a part of the forwarded DMZ eg. www.

http://www.e-infomax.com/ipmasq/howto/m-html/ipmasq-HOWTO-m.html

Ohh yea put those windows boxen on the net and you will be shot. I'm
tired of being probed by nimda and code red worms.





> 
> I would like to setup a linux box as gateway - firewall and 
> NAT (maybe DHCP too) for a network of SUN workstations, 
> windoze (98, XP, 2000) PC's and macs. 
> 
> I don't care about win and macs but would want the SUN 
> network to be as secure as possible. As I guess win can be 
> easily compromised, I thought of physically 
> separating the unix network from the others by using three 
> network cards on the gateway. So having two private networks, 
> I can filter what goes from one to the other with 
> the gateway's firewall.
> 
> Is this the right way to do what I would like? Any 
> recommandation would be welcome.
> 
> Thanks,
> David Bourgeois
> 
> 
> 



^ permalink raw reply	[flat|nested] 4+ messages in thread

* Advice on network config (unix - linux and windows - mac)
@ 2002-10-14 12:58 David Bourgeois
  2000-10-16 22:20 ` Rowan Reid
  0 siblings, 1 reply; 4+ messages in thread
From: David Bourgeois @ 2002-10-14 12:58 UTC (permalink / raw)
  To: netfilter

I would like to setup a linux box as gateway - firewall and NAT (maybe DHCP too) for a network of SUN workstations, windoze (98, XP, 2000) PC's and macs. 

I don't care about win and macs but would want the SUN network to be as secure as possible. As I guess win can be easily compromised, I thought of physically 
separating the unix network from the others by using three network cards on the gateway. So having two private networks, I can filter what goes from one to the other with 
the gateway's firewall.

Is this the right way to do what I would like? Any recommandation would be welcome.

Thanks,
David Bourgeois




^ permalink raw reply	[flat|nested] 4+ messages in thread

* Advice on network config (unix - linux and windows - mac)
@ 2002-10-14 15:55 David Bourgeois
  2002-10-15  4:53 ` Nuitari
  0 siblings, 1 reply; 4+ messages in thread
From: David Bourgeois @ 2002-10-14 15:55 UTC (permalink / raw)
  To: netfilter

I would like to setup a linux box as gateway - firewall and NAT (maybe DHCP too) for a network of SUN workstations, windows (98, XP, 2000) PC's and macs. 

I don't care about win and mac 's security but would like the SUN network to be as secure as possible. As I guess win can be easily compromised or in our case, untrusted 
persons can have access to it so I thought of physically separating the unix network from the others by using 2 subnets (three network cards on the gateway). So having 
two private networks, I can filter what goes from one to the other with the gateway's firewall (iptables in my case)

Is this the right way to do what I would like? Do you see any problem pointing out? Any recommandation would be welcome.

Thanks,
David Bourgeois






^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: Advice on network config (unix - linux and windows - mac)
  2002-10-14 15:55 David Bourgeois
@ 2002-10-15  4:53 ` Nuitari
  0 siblings, 0 replies; 4+ messages in thread
From: Nuitari @ 2002-10-15  4:53 UTC (permalink / raw)
  To: netfilter

On Mon, 14 Oct 2002, David Bourgeois wrote:

> I would like to setup a linux box as gateway - firewall and NAT (maybe
> DHCP too) for a network of SUN workstations, windows (98, XP, 2000) PC's
> and macs.
> 
> I don't care about win and mac 's security but would like the SUN
> network to be as secure as possible. As I guess win can be easily
> compromised or in our case, untrusted persons can have access to it so I
> thought of physically separating the unix network from the others by
> using 2 subnets (three network cards on the gateway). So having two
> private networks, I can filter what goes from one to the other with the
> gateway's firewall (iptables in my case)
> 
> Is this the right way to do what I would like? Do you see any problem
> pointing out? Any recommandation would be welcome.
> 
> Thanks,
> David Bourgeois

You should have security for the windows/mac on the firewall itself.
If you can, get a mail filter to remove some of the problems with security 
in windows.

Your idea is sound, but don't forget to treat traffic coming from the 
mac/win part as being traffic from the internet (and vice-vesa).

Also make sure that the physical network is distinct (eg 1 network card 
for the sun network, 1 for internet, 1 for win/mac).





^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2002-10-15  4:53 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2002-10-14 12:58 Advice on network config (unix - linux and windows - mac) David Bourgeois
2000-10-16 22:20 ` Rowan Reid
  -- strict thread matches above, loose matches on Subject: below --
2002-10-14 15:55 David Bourgeois
2002-10-15  4:53 ` Nuitari

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox