buil a solaris-based firewall


I'm planing to build a firewall by using one ultra 60 solaris 9 installed with Ipfitler.
The box a LAN card builtin and I would like to add another card (PCI card). The Buil-in (interface hme0) will go out to INTERNET through ISP (for instace: ext IP:
The extra PCI card (eth1) will connect to a switch and then to my LAN included: 1 webserver, 1 database server, 1 FTp server, 1 mail server.

What configuration i should put on the eth1 card as well as my servers?
beside that, I'm not sure about hardware compatibility between SUN and any kind of PCI network card.

Can you expertes give me some insight?

Thanks alot. I'm grateful for your help
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

1) You may find some drivers for your PCI card. At least there is working 3COM driver for 3c905c ( http://sol-enet.sourceforge.net/index.shtml  http://www.confusioncentral.com/ethernet/ethernet.html ), it works. Some Solaris features are unavailable with this card, but you hardly need to worry about it.
2) Configuring ipfilter on Solaris is the same as on any other system. You should configure NAT. Read HOWTO: http://www.obfuscation.org/ipf/ipf-howto.html#TOC_29

valleytechAuthor Commented:
thanks for your comments.
My point is that: for instance

one eht0: i ipconfig like this:
dns: provided by my ISP

on eth1: what subnet mask should it be? (simply What are gateway, primary dns and secondary dns for this inteface?

ON OTHER SERVERS (web, database)

are those correct?
thanks alot
1) eth0 and eth1 are hardly network interface names on Solaris, just to be shure that you understand this :-)
2) not ipconfig, but ifconfig is used on Solaris to configure interfaces. man ifconfig
3) Solaris has system wide resolver, it's not an attribute of  your network card. So you will use only external ISP's DNS.
4) Netmask depends on your LAN design preferences only. And Yes is a correct value for 192.168.x.x network.
5) On other servers there will be many addresses, gateway is correct, DNS server should be also be the same as on Solaris host.


Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Why not Solaris 10 ??? Why stick with old release for fresh instalation?

For any PCI netcard support:
Better ipfilter for Ultra 60:
Not ipfilter, but mostly compatible with ipfilter config:

Athlon/Opteron will be cheaper today.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.