Link to home
Start Free TrialLog in
Avatar of valleytech
valleytechFlag for United States of America

asked on

buil a solaris-based firewall

dear,

I'm planing to build a firewall by using one ultra 60 solaris 9 installed with Ipfitler.
The box a LAN card builtin and I would like to add another card (PCI card). The Buil-in (interface hme0) will go out to INTERNET through ISP (for instace: ext IP: 209.172.108.6)
The extra PCI card (eth1) will connect to a switch and then to my LAN included: 1 webserver, 1 database server, 1 FTp server, 1 mail server.

What configuration i should put on the eth1 card as well as my servers?
beside that, I'm not sure about hardware compatibility between SUN and any kind of PCI network card.

Can you expertes give me some insight?

Thanks alot. I'm grateful for your help
Avatar of Arty K
Arty K
Flag of Kazakhstan image

1) You may find some drivers for your PCI card. At least there is working 3COM driver for 3c905c ( http://sol-enet.sourceforge.net/index.shtml  http://www.confusioncentral.com/ethernet/ethernet.html ), it works. Some Solaris features are unavailable with this card, but you hardly need to worry about it.
2) Configuring ipfilter on Solaris is the same as on any other system. You should configure NAT. Read HOWTO: http://www.obfuscation.org/ipf/ipf-howto.html#TOC_29

Avatar of valleytech

ASKER

thanks for your comments.
My point is that: for instance

one eht0: i ipconfig like this:
ip: 209.172.108.4
dns: provided by my ISP

on eth1: 192.168.1.1. what subnet mask should it be? (simply 255.255.255.0??). What are gateway, primary dns and secondary dns for this inteface?

ON OTHER SERVERS (web, database)
eth0: 192.168.1.2
gateway: 192.168.1.1

are those correct?
thanks alot
ASKER CERTIFIED SOLUTION
Avatar of Arty K
Arty K
Flag of Kazakhstan image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial