Linux Netfilter discussions
 help / color / mirror / Atom feed
* Isolate a legacy machine
@ 2003-10-16 22:02 Ringer, Torleiv
  2003-10-17  3:15 ` Bridge question Herman
                   ` (2 more replies)
  0 siblings, 3 replies; 9+ messages in thread
From: Ringer, Torleiv @ 2003-10-16 22:02 UTC (permalink / raw)
  To: netfilter

Hi there,

I am not exactly sure how this needs to be done...

I have a legacy machine that I need to isolate from our LAN. Network access to this machine will be limited to port forwarding of telnet, and a limited FTP access that will only be initiated locally on a proxy machine (which will also run the iptables).

Let's say that the legacy machine currently has address 10.2.1.100, and I would like my proxy/firewall to have the same address. I will be unplugging the legacy machine from the LAN, then assigning the proxy/firewall the same IP.

Can I isolate the 100 machine from the LAN, and keep the same IP? I need to do this for failover, so that if the proxy box goes down, I can just unplug the 100 machine from the proxy/firewall, and plug it back into the LAN. I would also be unplugging the proxy/firewall from the LAN at this point.

Can I port forward telnet from the LAN (eth0) side to the legacy (eth1) side where both the proxy machine and the legacy machine have the same IP but are isolated from each other? Is this impossible?

Torleiv Ringer
IT Support
Minnesota Public Radio
http://www.mpr.org



^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2003-10-17 13:52 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-10-16 22:02 Isolate a legacy machine Ringer, Torleiv
2003-10-17  3:15 ` Bridge question Herman
2003-10-17  3:46   ` Mark E. Donaldson
2003-10-17  8:39   ` tsh
2003-10-17 13:49     ` Herman
2003-10-17 13:37   ` Jeremy Jones
2003-10-17 13:52     ` Herman
2003-10-17  3:52 ` Isolate a legacy machine Bill Chappell
2003-10-17  4:37 ` Joel Newkirk

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox