[x]
Posted via EE Mobile

Search, ask, and monitor your questions on the go with EE Mobile. Visit Experts Exchange from your mobile device and never be out of touch again.

Question
[x]
Attachment Details
[x]
The Solution Rating System

With so many solutions, how can you tell which solutions are most likely to help you and which ones are not? To provide you with a tool to use, we rate our solutions based on various elements that most accurately determine if a solution is a quality solution. To explain what factors affect the solution rating, here are the elements we take into consideration when formulating our solution rating.

  • The Grade of the Solution
  • The Zone Rank of the Expert Providing the Solution
  • The Number of Author and Expert Comments
  • The Number of Experts Contributing
  • The Feedback of the Community

Your Input Matters
Because of the way the system is set up, the most important variable in this equation is you. As a member of Experts Exchange, you are able to cast your vote on the quality of the solutions in regard to how complete, accurate, helpful and easy to understand each solution is. When you provide your feedback, each rating is adjusted accordingly. So, if you see a solution that has a poor rating that you think is a good solution, let us know by rating it. As you do, the rating will be adjusted and will become more accurate for other members of our site.

If you have any suggestions that you would like to make for our rating system, please ask a question in the Suggestions Zone of Community Support.

Thank you!

6.6

Strictly Secured Network Design (Any better ways ?)  - Basic Network Architecture

Asked by deya in Linux Networking

Tags: smc

Dear All,

I would like to setup a network to the outside world as follows:

               WAN
                  |
                  |
              Router R1 (Router + Firewall, SMC Network Router )
         (external id: a.b.c.d, internal id : 192.168.2.1/255.255.2550 ) (Network A) (Linux Servers Redhat 9.0)
                  |
  ---------------------------------------------------------------
 |                         |                 |                                   |
 HTTP                Mail              FTP                                |
 Server              Server        Server                             |
                                                                                 |
                                                                                 |
                                    Network Internal (Need access to Internet, with web,ftp,telnet, and msn. (Network B) (MS Windows)
                                             192.168.3.X / 255.255.255.0
                                        This network, B, also needs access to network C. Network C, should not access the internet, or have any
                                         one able to access it   from the internet or from Network A.
                                         EXCEPTION:  is one computer on net C which only delivers mail through smtp to the internet,                                      
                                                                                 |
                                                                                 |
                                                    Network 192.168.168.X/255.255.255.0 (Network C)
                                                            Only clients on Network B should be able to access it.
                                          EXCEPTION: is one computer (DBServer) on net C which should accept database connections
                                          through port 1521 only and only from the HTTP Server on Network A. This copmuter, DBServer, also
                                          accepts connections from Network B through any other port So this computer is different than the
                                          other computers in Network C, in that it will only accept a connection from Network A from the HTTP
                                         server.

Now, the questions I have:

1. I want to achieve the maximum security in the network, especially to network C.
    Can I control the router, so that it will only accept connectiions from Network A, not C or A. In this case, how
    do I setup Network B ? Do I define a gateway for network B to forward to Network A ? and how to achive this, or do I define
    a route to network A ? (how too?)
2. How to connect from B to C ? Define a route or a gateway ?
3. How to handle name resolution ? Do I define three in each network , or a nameserver forwarder ?
4. Is it better to have a firewall between each network ? How or what kind of setup is required then ?
5. Is it better to use a DHCP for network B ? or leave it static as it is now ?
6. Can I selectively enable and disable computers in Network B to see network C ?
7.  Is it better to define a DMZ on Network A than NATting it with the router ?
8. Do I need two other routers for Network B and C ?
9. The best and most flexible option ?
10. For network B if I set it up this way, What should be the gateway ? should it be the router or the proxy server ?
11. How to setup the interaction for the clients and the different networks ?
12. Do I need a router for each network, or use a static route (how) ? How to define how the networks interact with each others
with restrictions and rules applied ? I would also like not to complicate the network very much, unless I have to for security reasons.

Basically, the main question would be how to implement such a network, and what details do I need to go through in terms of
commands and instructions / tools. Just to be in the right direction, I need to find out the best option that could be impolemented
in this case. For example, network A what are the setup parameters of it, network B, what is the gateway, dns ....etc and how can network B work with both network A and C, how to define the routing tables in this case ..etc.

All the Firewalls or Routers are SMC, not a computer, so we cannot use iptables or other firewalls.
Network C have computers running Linux / Sun / Windows Servers.

Network A is setup and running now,
Network B and C are both compined in the same network, running ip 192.168.68.X / 255.255.255.0. they will be split to two
networks, as the main domain server for the company is running in network C, and all computers on network B should connect to
to be granted logon to the domain.

I appreciate your help,

Thanks,


[+][-]08/07/03 10:10 AM, ID: 9101614Accepted Solution

View this solution now by starting your 30-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

About this solution

Zone: Linux Networking
Tags: smc
Sign Up Now!
Solution Provided By: Redimido
Participating Experts: 2
Solution Grade: A
 
[+][-]08/07/03 10:22 AM, ID: 9101700Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]08/07/03 10:48 AM, ID: 9101921Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]08/07/03 11:03 AM, ID: 9102040Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]08/07/03 12:44 PM, ID: 9102766Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]08/07/03 11:23 PM, ID: 9106016Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]08/08/03 07:39 AM, ID: 9108501Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]08/08/03 08:01 AM, ID: 9108671Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]08/08/03 08:06 AM, ID: 9108708Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]08/08/03 08:53 AM, ID: 9109113Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]08/08/03 11:21 AM, ID: 9110180Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]08/08/03 11:59 AM, ID: 9110412Assisted Solution

Assisted solutions are selected by the member who asked the question as a comment that contributed to their question's solution.

Start your 30-day free trial to view this Assisted Solution or ask the Experts your question.

 
[+][-]08/08/03 12:46 PM, ID: 9110701Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]08/08/03 01:06 PM, ID: 9110811Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]08/09/03 07:27 AM, ID: 9113738Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]08/09/03 07:51 AM, ID: 9113790Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]08/09/03 08:39 AM, ID: 9113975Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]08/09/03 08:50 AM, ID: 9114020Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]08/09/03 09:18 AM, ID: 9114128Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]08/09/03 09:44 AM, ID: 9114198Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]08/09/03 09:55 AM, ID: 9114251Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]08/09/03 09:56 AM, ID: 9114253Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]08/09/03 10:15 AM, ID: 9114325Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]08/09/03 12:21 PM, ID: 9114685Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]08/09/03 02:14 PM, ID: 9115000Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]08/09/03 03:03 PM, ID: 9115189Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]08/09/03 03:04 PM, ID: 9115196Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]08/09/03 08:02 PM, ID: 9115832Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]08/09/03 09:16 PM, ID: 9116029Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]08/09/03 09:23 PM, ID: 9116040Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04/15/05 01:36 PM, ID: 13794332Administrative Comment

Experts Exchange has a courteous staff of administrators who help members get the most out of the website by means of administrative comments like this one.

Start your 30-day free trial to view this Administrative Comment or ask the Experts your question.

 
[+][-]04/19/05 10:43 AM, ID: 13817990Administrative Comment

Experts Exchange has a courteous staff of administrators who help members get the most out of the website by means of administrative comments like this one.

Start your 30-day free trial to view this Administrative Comment or ask the Experts your question.

 
 
Loading Advertisement...
20091021-EE-VQP-81