buil a solaris-based firewall

Posted on 2006-04-24
Last Modified: 2013-12-23

I'm planing to build a firewall by using one ultra 60 solaris 9 installed with Ipfitler.
The box a LAN card builtin and I would like to add another card (PCI card). The Buil-in (interface hme0) will go out to INTERNET through ISP (for instace: ext IP:
The extra PCI card (eth1) will connect to a switch and then to my LAN included: 1 webserver, 1 database server, 1 FTp server, 1 mail server.

What configuration i should put on the eth1 card as well as my servers?
beside that, I'm not sure about hardware compatibility between SUN and any kind of PCI network card.

Can you expertes give me some insight?

Thanks alot. I'm grateful for your help
Question by:valleytech
    LVL 27

    Expert Comment

    1) You may find some drivers for your PCI card. At least there is working 3COM driver for 3c905c ( ), it works. Some Solaris features are unavailable with this card, but you hardly need to worry about it.
    2) Configuring ipfilter on Solaris is the same as on any other system. You should configure NAT. Read HOWTO:


    Author Comment

    thanks for your comments.
    My point is that: for instance

    one eht0: i ipconfig like this:
    dns: provided by my ISP

    on eth1: what subnet mask should it be? (simply What are gateway, primary dns and secondary dns for this inteface?

    ON OTHER SERVERS (web, database)

    are those correct?
    thanks alot
    LVL 27

    Accepted Solution

    1) eth0 and eth1 are hardly network interface names on Solaris, just to be shure that you understand this :-)
    2) not ipconfig, but ifconfig is used on Solaris to configure interfaces. man ifconfig
    3) Solaris has system wide resolver, it's not an attribute of  your network card. So you will use only external ISP's DNS.
    4) Netmask depends on your LAN design preferences only. And Yes is a correct value for 192.168.x.x network.
    5) On other servers there will be many addresses, gateway is correct, DNS server should be also be the same as on Solaris host.

    LVL 61

    Assisted Solution

    Why not Solaris 10 ??? Why stick with old release for fresh instalation?

    For any PCI netcard support:
    Better ipfilter for Ultra 60:
    Not ipfilter, but mostly compatible with ipfilter config:

    Athlon/Opteron will be cheaper today.

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Highfive + Dolby Voice = No More Audio Complaints!

    Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

    #Citrix #Citrix Netscaler #HTTP Compression #Load Balance
    If your business is like most, chances are you still need to maintain a fax infrastructure for your staff. It’s hard to believe that a communication technology that was thriving in the mid-80s could still be an essential part of your team’s modern I…
    Learn how to navigate the file tree with the shell. Use pwd to print the current working directory: Use ls to list a directory's contents: Use cd to change to a new directory: Use wildcards instead of typing out long directory names: Use ../ to move…
    Here's a very brief overview of the methods PRTG Network Monitor ( offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

    759 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    9 Experts available now in Live!

    Get 1:1 Help Now