Help setting up a dedicated IPtables firewall

From: Frank Harris (phrankster@hotmail.com)
Date: 12/11/02


From: phrankster@hotmail.com (Frank Harris)
Date: 11 Dec 2002 12:35:42 -0800

I am currently running an IPtables firewall on a Red Hat 8.0 Linux
server that also houses mail, dns and web services for multiple
virtual hosts. I am planning on separating each service onto it's own
dedicated server, however, I would prefer to not setup an IPtables
firewall on each machine. Instead, I would like a dedicated Linux
server for firewalling between my internet router and the other
servers. I also want to allow other services into some of the machines
(such as ssh and ftp).

I suspect I need two NIC cards for the firewall. One that can talk on
the same network as the internet router, and the other that can talk
to the rest of the servers on my network.

This is an example of what I'm trying to accomplish:

router.somedomain.com 198.123.50.1
firewall1.somedomain.com 198.123.50.2 (nic card 1- external)
firewall2.somedomain.com 192.168.1.1 (nic card 2- internal)

  (servers behind firewall)
  ns1.somedomain.com 192.168.1.5 (allow dns,ssh)
  ns2.somedomain.com 192.168.1.6 (allow dns,ssh)
  mail1.somedomain.com 192.168.1.10 (allow pop3,smtp,ssh)
  mail2.somedomain.com 192.168.1.11 (allow pop3,smtp,ssh)
  www.somedomain.com 192.168.1.20 (allow http,https,ssh)

I would prefer to not use NAT, but I'm not sure if it's a requirement
for the type of firewall/network configuration I want to have.

I'm not entirely sure how to approach this. I'm not real familiar with
IPtables (I used NARC to configure my existing firewall), so I will
need some working examples (or at least some resource I can
reference).

Thanks for your help in advance.
Frank



Relevant Pages

  • Re: Linux or BSD alternative to Windows Home Server
    ... My questions were about Gentoo vs. Linux for a sever, ... I will probably eventually have a dedicated firewall ... if you were to have a file server which is accessible ... I'm aware that I could probably create scripts to regularly backup ...
    (comp.os.linux.misc)
  • Re: Feedback solicited - best way to harden a mail/web server?
    ... Was the system protected by a properly configured firewall? ... it's not a bad "starting point" and it can generate an IPtables rule ... > nor is there a web or ftp server; aside from that I haven't tried to secure ... Before I'll install some nifty application ...
    (comp.os.linux.security)
  • Re: LINUX Firewall
    ... there is merit on not having your SBS ... linux firewall server in really doesn't offer any additional security. ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: Linux box as firewall
    ... PPTP VPN server ... Support for CGI and PHP ... Subject: Linux box as firewall ... > elegant in design than Linux. ...
    (Security-Basics)
  • Re: CEICW fails at firewall config
    ... Do you or do you not have ISA 2000 or ISA 2004 installed on the SBS server? ... Do you have 2 NICs in the SBS? ... CEICW fails on firewall configuration every time. ... >>> Call to Creating the protected networks access rule returned ok. ...
    (microsoft.public.windows.server.sbs)