Solved

IPCOP Configuration / Firewall

Posted on 2010-08-25
11
1,360 Views
Last Modified: 2012-05-10
I am setting up an IPCOP firewall, but having a few issues.

My set up is green/red

I want Green to be on a 10.10.10.1/24 network & Red plugged in to a router (switch) on a 192.168.0.1/24 (external IP on router is static)
I have read that if the red is Static,  i need to enter the Primary/Secondary DNS + gateway address of router (by doing this, i am not sure how the red knows about the 192.168.0.1/24 network or this is just the gateway to the internet)
Would it work ok if i set up red on DHCP?

Even if the Red is not working, i should at least be able to connect to the IPCOP box on the 10.10.10.0/24 Network, but even that is not working!
Can't even ping it

Has anybody successfully install IPCOP in this type of Network?

Cheers
0
Comment
Question by:defrey
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
  • 2
  • +1
11 Comments
 
LVL 4

Expert Comment

by:tzwimfam
ID: 33518730
I leave Red set to DHCP and allow my isp to assign it an IP address.  
Are you sure you know which one is green and red?  I had that problem once.
0
 
LVL 1

Author Comment

by:defrey
ID: 33518839
Not 100 % sure, how do you find out?
0
 
LVL 9

Expert Comment

by:Barry Gill
ID: 33518877
the BEST thing to do is got to your ifcfg-eth0 and ifcfg-eth1 files, edit them and bind the MAC address of each interface to a file.
This way you are guaranteed an interface no matter what.
If the version of IPCOP you are on is 2.0 or greater, you should in fact have this mac binding already. You just need to identify which of the NICs is which.

Also, that config is very common, there should be no issues with it.
You may not be able to ping it because afaik ping is not enabled by default.
Also check that you have enabled routing between the interfaces.
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 1

Author Comment

by:defrey
ID: 33519052
Would you recommend to use IPCOP version 2.0 or higher instead of 4.2.1?
0
 
LVL 9

Expert Comment

by:Barry Gill
ID: 33519110
the 1.4 range still uses a very outdated version of the linux kernel, 2.4.
The last changes logged for 1.4.21 were logged in July 2008.

Personally I wouldn't be using that at all.
I would rather build a CentOS server with no additional services and install smoothwall.
(if you have great linux skills, custom build a Gentoo linux server with smoothwall...)

From: http://www.ipcop.org/2.0.0/en/admin/html/whatsnew.html
1.3. What's New in v2.0?

IPCop v2.0 is a development of v1.4, but incorporates some significant improvements.

    *      Linux kernel 2.6.27
    *      New hardware support, including Cobalt, sparc and PPC platforms.
    *      New installer, which allows you to install to flash or hard drives, and to select interface cards and assign them to particular networks.
    *      Access to all web interface pages is now password protected.
0
 
LVL 1

Author Comment

by:defrey
ID: 33519267
Dont have any Linux Skills at all!
Shall i go for IPCOP V2.0?
0
 
LVL 4

Accepted Solution

by:
tzwimfam earned 500 total points
ID: 33519328
I am happy with 1.4.21 and it should work for you.  You should be able to set red to dhcp and if you can't connect to the green have you tried switching the cables to check to see if red and green are where you think they are?
0
 
LVL 9

Expert Comment

by:Barry Gill
ID: 33519951
If you have no linux skills then stick with it, just go edit your ifcfg-eth files and add mac addresses into them so you never have an accidental swap of interfaces.
from /etc/sysconfig/network-scripts/ifcfg-eth1
# devicename
DEVICE=eth1
HWADDR=xx:xx:xx:xx:xx:xx
BOOTPROTO=static
IPADDR=x.x.x.x
NETMASK=255.255.255.0
GATEWAY=XXX.XXX.XXX.XXX
HOSTNAME=node-name.name-of-domain.com
DOMAIN=name-of-domain.com

The line you need to make sure is there is HWADDR=mac address, you can get the MAC address from the command ifconfig

0
 
LVL 10

Expert Comment

by:pfrancois
ID: 33529615
The green interface is eth0, the red one is eth1. IPCop works even if red is down.

An easy way to see which interface is connected is to connect only one network interface and to look at the output of "ifconfig eth0" and "ifconfig eth1". You will see traffic on the connected interface because the number near to RX bytes and TX bytes is increasing in the output of ifconfig:

eth0      Link encap:Ethernet  HWaddr 00:xx:xx:xx:xx:xx  
          inet addr:10.10.10.1  Bcast:10.10.10.255  Mask:255.255.255.0
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:1702900 errors:0 dropped:0 overruns:0 frame:0
          TX packets:2418525 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000
          RX bytes:244771020 (233.4 MB)  TX bytes:2818471625 (2687.9 MB)
          Interrupt:5 Base address:0x1400

(I suppose the IP address of your green interface is 10.10.10.1)

If you don't understand what I mean with "run ifconfig", you can also surf to IPCop at the webpage through the green interface:

https://10.10.10.1:443/cgi-bin/netstatus.cgi

and you will see the output of ifconfig for each interface. If nothing happens, you probably are connected to the red interface. Connect to the green interface and you will be able to see that webpage.
0
 
LVL 10

Expert Comment

by:pfrancois
ID: 33584976
@defrey: Have you solved your problem? If your setup is correct, you can connect a laptop/desktop on the green interface, even if the red interface is down and receive an IP address. If you have doubts on which NIC is red and which is green, just try to connect your laptop/desktop at both: only one will give you an IP address through DHCP.
0
 
LVL 1

Author Closing Comment

by:defrey
ID: 33722544
none
0

Featured Post

Is your NGFW recommended by NSS Labs?

Ours is! NSS Labs Next Generation Firewall Test gives the WatchGuard Firebox M4600 a "Recommended" rating! Curious where your NGFW landed on the  Security Value Map? See the map and download the full report today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Occasionally, we encounter connectivity issues that appear to be isolated to cable internet service.  The issues we typically encountered were reset errors within Internet Explorer when accessing web sites or continually dropped or failing VPN conne…
Imagine you have a shopping list of items you need to get at the grocery store. You have two options: A. Take one trip to the grocery store and get everything you need for the week, or B. Take multiple trips, buying an item at a time, to achieve t…
In this video, viewers are given an introduction to using the Windows 10 Snipping Tool, how to quickly locate it when it's needed and also how make it always available with a single click of a mouse button, by pinning it to the Desktop Task Bar. Int…
This is my first video review of Microsoft Bookings, I will be doing a part two with a bit more information, but wanted to get this out to you folks.

729 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question