• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 240
  • Last Modified:

IP routing

Our new Wi2K server installed two NIC ,

-One NIC connected to internal LAN ( 192.168.66.182)
-One NIC connected to another network ( 192.168.1.110) and new internet circuit.

This server will share two services, one of internal network print server  and another for FTP server.
Now I plan setup new internet circuit only for FTP download.

Please advice how to setup the ip routing.



0
itjackiewong
Asked:
itjackiewong
  • 4
  • 2
  • 2
1 Solution
 
gurutcCommented:
Hi,

Here's a start:  

Only define a default gateway on the server for the external network, ie the 192.168.1.x network.

And, to disable routing for stations on the internal subnet, ie the 192,168.66.x network, set the following value:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\"

Set the DWORD value for IPEnableRouter=0

This is a good start for you.

- gurutc
0
 
gurutcCommented:
That registry value is set on the server with the 2 nics.

- gurutc
0
 
banks1850Commented:
Did you want to be able to connect to the external segment from the internal?  If yes, then you should probably set up a DMZ instead of this.  Bridging this way leads to security holes.  If not then it's not a problem, although there is still a security hole here as you are opening one service to the internet and another to an internal network with essentially no security between the two.  Just wanted you to know all the facts about dual homed Servers.
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
itjackiewongAuthor Commented:
qurutc
- i plan setup a router in NIC 2 (192.168.66X)  and port forward to NIC 2 IP address.

Banks1850
- Internal network user only copy the files to the folder in server
- Internet can via router port forward connected to NIC2 (192.168.66.X) ,connected to FTP SERVER download folder file.

Please advice the solution.
0
 
itjackiewongAuthor Commented:
Hi qurutc

Please advice how to modify registry in our server, because 2 nic install on same server.
0
 
gurutcCommented:
Hi,

To run regedit, just click Start Run and type in regedit and press enter.  Then browse to the key above.

- gurutc
0
 
banks1850Commented:
Yes, I would probably set up a DMZ for this, just to keep things safer.  you can set up the Server in the DMZ, set up port forwarding on your external facing firewall, and set up an internal rule for the internal facing file share.  This will keep the server separate from your internal domain and would eliminate the need for 2 nic cards as well.  the port for file sharing through the dmz for internal users would be 445 I believe.
0
 
gurutcCommented:
I agree about the DMZ.  

- gurutc
0

Featured Post

Vote for the Most Valuable Expert

It’s time to recognize experts that go above and beyond with helpful solutions and engagement on site. Choose from the top experts in the Hall of Fame or on the right rail of your favorite topic page. Look for the blue “Nominate” button on their profile to vote.

  • 4
  • 2
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now