Re: [suse-security] Setting up firewall with DMZ

/ 2004-01-09 15:21:19 +0200
\ Jaakko Tamminen:
> Hi All
> I'm facing a new situation.
> A company need to add to their current network a DMZ zone.
> Currently there is ADSL-modem with firewall, and LAN with C-class networking. 
> The ADSL/firewall is visible with IP
> Now I would like to connect a SuSEfirewall2 with DMZ between the ADSL/firewall 
> and the LAN, thus enabling a DMZ zone with a web-shop application.
> Could someone quide me with subnets, what to choose.. I'm little puzzled 
> here... 
> I believe the DMZ should have either A or B class..?
> Should I change the ADSL also to for example A-class, so that I would have 
> first A-class coming inward from the ADSL, then B-class for the DMZ, and 
> C-class for the LAN?

there is more to ip routing than just A,B,C ...

iiuc, you have now
	[ LAN: ], expecting their default gw at

so you could choose to put in your 
	FW:  here, and connect it additionally to

for example your
	[ DMZ: ]

as well as via the third nic to your ADSL router, which you could
reconfigure to announce itself as ...
that way you won't even need to reconfigure your existing lan clients.

you end up with

                `- - SuSE FW -
                                   /          \
                                 /               \- - server1
                               LAN               \- - server2
           box1 - -/                 \- - server3
           box2 - -/
           box3 - -/

both DMZ and LAN may be distinct class C networks
you of course can choose otherwise,
and use for the DMZ, if you like :)


	Lars Ellenberg

