public inbox for gentoo-user@lists.gentoo.org
 help / color / mirror / Atom feed
From: Willie Wong <wwong@Princeton.EDU>
To: gentoo-user@lists.gentoo.org
Subject: Re: [gentoo-user]  Re: [Iptables related] How to make one machine only talk on loc lan
Date: Mon, 14 Nov 2005 00:39:36 -0500	[thread overview]
Message-ID: <20051114053936.GE12256@princeton.edu> (raw)
In-Reply-To: <87zmo8i0jk.fsf@newsguy.com>

On Sun, Nov 13, 2005 at 05:35:27PM -0600, Harry Putnam wrote:
> In the different scenarios we've been discussing though, I'm thinking
> I've blocked internet access for several machines.  If those machines
> are then set to proxy thru a local lan address (The gentoo box running
> squid).  They would be able to contact that address.  As I understand
> it, that is the only address they would see.

So you are thinking:
  1) Block internet access of all kinds for the three windows boxes.
  2) Leave the internet access open for the Gentoo box. 
  3) Have squid running on the Gentoo box. 
So that if the Windows boxes want to access the internet, it goes
through the Gentoo box? 

Yes it would work. A pretty good idea from what I can see. 
> 
> And if the proxy were turned off in software they would then not be
> able to go to internet either since that avenue is already blocked.
> So the browser would stall and show no internet connection.
> 


> I'm not sure what you mean here about the infinite loop.  Thats what
> routers do is foward traffic to machines behind them.
> 
> What I'm thinking when I talk about setting default route to the
> gentoo box is that the router is also a switch.  I'm wondering if
> internet bound packets can:
> 
> o start on a win box behind the router
> o get to the router/switch
> o be switched to the gentoo box since it is the gateway listed
> o be sent back to the router by the gentoo box on its journey to
>   INET. 
> 
> Is that even possible without another subnet, nic etc?
> 
The question is: when you say the gateway listed, do you mean the
gateway listed for the router or the gateway listed for the win box?
If for the win box, it is trivial to change the gateway to the router,
and since the router speaks to the internet, you are down to no
protection. If you mean the gateway for the router.... imagine: the
gentoo box passes a packet to the router, the router things the
gateway is the gentoo box, and passes the packet back...

Unless, of course, your router does forwarding per host, and my guess
is that your router can't do that (though I might very well be wrong).

I think you are trying to make it more complicated than it actually
is. If you just take the one method you suggested above: block of
services on the netgear and mandate internet access from the win boxes
go through squid on gentoo, I think it should be fine for what you
want. 

W
-- 
Seen in LINAC @ Fermi National Accelerator Laboratory:
  (A series of signs, each with a different "name")
 This 7833 Power Amplifier Tube is to be Called:
       Gassy
       Sparky
       Leaky
       Old Number 9
       Just Plain Dead
       Nick O'Tyme
Sortir en Pantoufles: up 1 day, 21:49
-- 
gentoo-user@gentoo.org mailing list



  reply	other threads:[~2005-11-14  5:44 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-11-12 23:35 [gentoo-user] [Iptables related] How to make one machine only talk on loc lan Harry Putnam
2005-11-12 23:17 ` John Jolet
2005-11-13  0:56   ` [gentoo-user] " Harry Putnam
2005-11-13  3:14     ` John Jolet
2005-11-13  7:09       ` Harry Putnam
2005-11-13  8:48         ` Willie Wong
2005-11-13 17:44           ` Harry Putnam
2005-11-13 18:26             ` Willie Wong
2005-11-13 21:13               ` Harry Putnam
2005-11-13 21:30                 ` Willie Wong
2005-11-13 23:35                   ` Harry Putnam
2005-11-14  5:39                     ` Willie Wong [this message]
2005-11-13 19:09           ` Harry Putnam
2005-11-13 15:17         ` Holly Bostick
2005-11-13  3:54     ` Willie Wong
2005-11-19 15:39 ` [gentoo-user] " A. Khattri
2005-11-21  4:26   ` [gentoo-user] " Harry Putnam

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20051114053936.GE12256@princeton.edu \
    --to=wwong@princeton.edu \
    --cc=gentoo-user@lists.gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox