public inbox for gentoo-user@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-user]  [Iptables related] How to make one machine only talk on loc lan
@ 2005-11-12 23:35 Harry Putnam
  2005-11-12 23:17 ` John Jolet
  2005-11-19 15:39 ` [gentoo-user] " A. Khattri
  0 siblings, 2 replies; 17+ messages in thread
From: Harry Putnam @ 2005-11-12 23:35 UTC (permalink / raw
  To: gentoo-user

Hopefully somehere can direct me to where this should be posted or
answer it directly.  I'm looking to my Gentoo box to solve the problem
described below:

First:
My home lan looks like:


                 INTERNET
                    |
                 DSLMODEM
                    |
------------- NETGEAR FVS318 fw/router---------------
 |       |        |        |       |

Mch1    Mch2     mch3    mch4     mch5      
Lin      win     win     win      win
Gentoo

Machines 3-5 are heavy hitters for graphics work and are heavily
loaded with such things as Photoshop, vegas, canopus Edius, Adobe
Illustrator and the like.

I don't want to have to worry about spyware,adware,virus prevention
firewall stuff competing for resources with the graphics tools.
Instead I'd like to prevent those three from contacting the internet.

I want to isolate mch3-5 to only the local network.

That is, only mch 1 (a linux) machine and mch2 (a winxp pro) machine,
should be able to freely access the internet. (Making those secure
while doing so is not dicussed here)  3-5 should only be able
to talk to/from the local net.

I realize this would not be true isolation as anyone getting to 1-2
would have access to 3-5, so all bets are off if that should happen.

Its more about having to worry about downloads or link clicks etc with
unwanted results.

The Netgear FVS318 appears not to be able to do this for me.  But I
could be wrong there.  I see no options that look usefull for it.
Blocking of sites might do it but appears it would be a long process
setting it up. 

I'd happily hear that the router can do this.

=====================================================

I'm turning to my gentoo box for a solution.  

However, I'm not interested in setting it up as the router for
everthing and ditching the NETGEAR.  Its to convenient having
something the size of a medium book that makes no noise or heat but
can keep all but the most dedicated of script kiddies of my network.

I'm thinking I could route machines 3-5 thru it as gateway.  
The way I work, the gentoo box is always running.  I would never be
using the others without it running, its just how I work.

I know already that Iptables can handle the rulesets needed to get
what I want.  I'm not sure of the exact rules yet but believe it is at
least possible.

Now for the questions:

Can I route 3-5 thru the Gentoo box without changing the subnet
setup?  That is, all still remain 192.168.0.0/24.  And simply set
gateway on 3-5 to point at the gentoo box.  Then setup IPtables to
prevent those machines from talking beyond local lan in or out.

Something like deny everything, then allow only a list of `safe' IPs
on the local lan.

So again:
Can I do all this without hardwiring 3-5 direct to the Gentoo box.
That is, just by setting it as gateway on each of them.

-- 
gentoo-user@gentoo.org mailing list



^ permalink raw reply	[flat|nested] 17+ messages in thread

end of thread, other threads:[~2005-11-21  4:35 UTC | newest]

Thread overview: 17+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-11-12 23:35 [gentoo-user] [Iptables related] How to make one machine only talk on loc lan Harry Putnam
2005-11-12 23:17 ` John Jolet
2005-11-13  0:56   ` [gentoo-user] " Harry Putnam
2005-11-13  3:14     ` John Jolet
2005-11-13  7:09       ` Harry Putnam
2005-11-13  8:48         ` Willie Wong
2005-11-13 17:44           ` Harry Putnam
2005-11-13 18:26             ` Willie Wong
2005-11-13 21:13               ` Harry Putnam
2005-11-13 21:30                 ` Willie Wong
2005-11-13 23:35                   ` Harry Putnam
2005-11-14  5:39                     ` Willie Wong
2005-11-13 19:09           ` Harry Putnam
2005-11-13 15:17         ` Holly Bostick
2005-11-13  3:54     ` Willie Wong
2005-11-19 15:39 ` [gentoo-user] " A. Khattri
2005-11-21  4:26   ` [gentoo-user] " Harry Putnam

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox