Possible to just filter packets on the same SUBNET?
Posted on 2004-08-19
we run about 15 servers on one network subnet 138.240.260.0. not physically the subnet for security reasons on experts-exchange. this is our logical setup though! We would like to hardware firewall 3 Servers with the ips 138.240.260.136, 138.240.260.137, 138.240.260.138. But the IP address cannot change. And we do not want to firewall the entire subnet so we do not effect the other servers. What is everyone's suggestion on the question? from what i know. a standard firewall will need 2 different networks on the front and back side. I've heard of a hardware device that could sit on the wire just for those 3 servers and strictly filter packets. While still not changing subnet or ips. It's a MUST that these IP address not change on the servers so that takes out the possiblity of NAT. Product suggestions? Or can we in fact do this on a standard firewall....