[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 314
  • Last Modified:

buil a solaris-based firewall


I'm planing to build a firewall by using one ultra 60 solaris 9 installed with Ipfitler.
The box a LAN card builtin and I would like to add another card (PCI card). The Buil-in (interface hme0) will go out to INTERNET through ISP (for instace: ext IP:
The extra PCI card (eth1) will connect to a switch and then to my LAN included: 1 webserver, 1 database server, 1 FTp server, 1 mail server.

What configuration i should put on the eth1 card as well as my servers?
beside that, I'm not sure about hardware compatibility between SUN and any kind of PCI network card.

Can you expertes give me some insight?

Thanks alot. I'm grateful for your help
  • 2
2 Solutions
1) You may find some drivers for your PCI card. At least there is working 3COM driver for 3c905c ( http://sol-enet.sourceforge.net/index.shtml  http://www.confusioncentral.com/ethernet/ethernet.html ), it works. Some Solaris features are unavailable with this card, but you hardly need to worry about it.
2) Configuring ipfilter on Solaris is the same as on any other system. You should configure NAT. Read HOWTO: http://www.obfuscation.org/ipf/ipf-howto.html#TOC_29

valleytechAuthor Commented:
thanks for your comments.
My point is that: for instance

one eht0: i ipconfig like this:
dns: provided by my ISP

on eth1: what subnet mask should it be? (simply What are gateway, primary dns and secondary dns for this inteface?

ON OTHER SERVERS (web, database)

are those correct?
thanks alot
1) eth0 and eth1 are hardly network interface names on Solaris, just to be shure that you understand this :-)
2) not ipconfig, but ifconfig is used on Solaris to configure interfaces. man ifconfig
3) Solaris has system wide resolver, it's not an attribute of  your network card. So you will use only external ISP's DNS.
4) Netmask depends on your LAN design preferences only. And Yes is a correct value for 192.168.x.x network.
5) On other servers there will be many addresses, gateway is correct, DNS server should be also be the same as on Solaris host.

Why not Solaris 10 ??? Why stick with old release for fresh instalation?

For any PCI netcard support:
Better ipfilter for Ultra 60:
Not ipfilter, but mostly compatible with ipfilter config:

Athlon/Opteron will be cheaper today.

Featured Post

New feature and membership benefit!

New feature! Upgrade and increase expert visibility of your issues with Priority Questions.

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now