IP routing

Our new Wi2K server installed two NIC ,

-One NIC connected to internal LAN ( 192.168.66.182)
-One NIC connected to another network ( 192.168.1.110) and new internet circuit.

This server will share two services, one of internal network print server  and another for FTP server.
Now I plan setup new internet circuit only for FTP download.

Please advice how to setup the ip routing.



itjackiewongAsked:
Who is Participating?
 
gurutcConnect With a Mentor Commented:
I agree about the DMZ.  

- gurutc
0
 
gurutcCommented:
Hi,

Here's a start:  

Only define a default gateway on the server for the external network, ie the 192.168.1.x network.

And, to disable routing for stations on the internal subnet, ie the 192,168.66.x network, set the following value:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\"

Set the DWORD value for IPEnableRouter=0

This is a good start for you.

- gurutc
0
 
gurutcCommented:
That registry value is set on the server with the 2 nics.

- gurutc
0
Cloud Class® Course: Python 3 Fundamentals

This course will teach participants about installing and configuring Python, syntax, importing, statements, types, strings, booleans, files, lists, tuples, comprehensions, functions, and classes.

 
banks1850Commented:
Did you want to be able to connect to the external segment from the internal?  If yes, then you should probably set up a DMZ instead of this.  Bridging this way leads to security holes.  If not then it's not a problem, although there is still a security hole here as you are opening one service to the internet and another to an internal network with essentially no security between the two.  Just wanted you to know all the facts about dual homed Servers.
0
 
itjackiewongAuthor Commented:
qurutc
- i plan setup a router in NIC 2 (192.168.66X)  and port forward to NIC 2 IP address.

Banks1850
- Internal network user only copy the files to the folder in server
- Internet can via router port forward connected to NIC2 (192.168.66.X) ,connected to FTP SERVER download folder file.

Please advice the solution.
0
 
itjackiewongAuthor Commented:
Hi qurutc

Please advice how to modify registry in our server, because 2 nic install on same server.
0
 
gurutcCommented:
Hi,

To run regedit, just click Start Run and type in regedit and press enter.  Then browse to the key above.

- gurutc
0
 
banks1850Commented:
Yes, I would probably set up a DMZ for this, just to keep things safer.  you can set up the Server in the DMZ, set up port forwarding on your external facing firewall, and set up an internal rule for the internal facing file share.  This will keep the server separate from your internal domain and would eliminate the need for 2 nic cards as well.  the port for file sharing through the dmz for internal users would be 445 I believe.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.