Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Enthusiast Zone > Networking > Network Design help / Questions

Network Design help / Questions
Thread Tools
Moderator Emeritus
Join Date: Dec 2000
Location: College Park, MD
Status: Offline
Reply With Quote
Dec 15, 2002, 03:52 AM
 
I'm working on redesigning my home network since we will be moving, and I'll no longer have my wireless secured just by how it is (in basement and large house / lot). Also, I'm doing serving, and I need to get the server off my lan.

This is what I've come up with so far.




I'm going to be setting up a custom firewall, partially for learning needs, partially because I didn't see anything that does all that I want.

1. Can the IDS go on the gateway itself, or does it have to be it's own box? If it is it's own box, where does it go?

2. I want to be able to tunnel to the private network, either from the wireless network (which will be outside the private network) or from wherever I happen to be. Can I run a VPN server on the server? It will be supplying 3-5 machines internally, and probably 1-2 externally. Is this the best setup for the wireless?

3. I may want more then 1 subnet on the private network depending on design and tinkering. I don't really want another NIC in that gateway, can I run them off the one NIC without any real issues?

4. Where should a caching proxy server and my network DNS server go? I will be running a web DNS server and backup on the servers, should I also hit those for DNS lookups from the client machines on my private network? Also, should the gateway run the caching proxy server, or should it be another machine inside the private lan?

5. I like being able to do ssh user@host. How hard is that to setup? I know it can be done with NIS, but as far as I am aware, that doesn't work very well with OSX. Can it be done with DNS?

6. If I want more then one base station for max coverage, what would be the best way to run those while still keeping security? A switch on that NIC and a cable to each, or what?

More questions will probably come later.

Thanks,

Scott
My website
Help me pay for college. Click for more info.
     
Fresh-Faced Recruit
Join Date: Nov 2002
Location: mentalspace
Status: Offline
Reply With Quote
Feb 6, 2003, 09:20 PM
 
Nice job ScotttheKing!

I was looking forward to reading the answers to Scott's post but there aren't any yet -- Sir Camelot? GPH? Or maybe Scott figured it out by now...?
The only dumkwestchun is the one you're afraid to ask.
     
Moderator Emeritus
Join Date: Dec 2000
Location: College Park, MD
Status: Offline
Reply With Quote
Feb 6, 2003, 09:33 PM
 
Originally posted by dumkwestchun:
Nice job ScotttheKing!

I was looking forward to reading the answers to Scott's post but there aren't any yet -- Sir Camelot? GPH? Or maybe Scott figured it out by now...?
I got a decent amount of answers on ars technica.
I'm actually going to make a few changes. I decided that I'm not building my own firewall, I'm going to use a linux firewall distro. Not as secure, but less work, and less places for me to make mistakes.

http://arstechnica.infopop.net/OpenT...p;r=2370998145
My website
Help me pay for college. Click for more info.
     
Administrator
Join Date: Apr 2001
Location: San Antonio TX USA
Status: Offline
Reply With Quote
Feb 7, 2003, 03:35 PM
 
The few insecurities in most Linux firewalls are relatively arcane, but you'll need to stay on top of them to keep secure. On the other hand, they're miles ahead of the way most people connect to the outside world, and even if there is no firewall distribution that's as secure as you want, you can tighten things yourself with some programing.

Cool network...
Glenn -----
OTR/L, MOT, Tx
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 09:10 PM.
All contents of these forums © 1995-2011 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.7 © 2000-2011, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2