Solved

Router / Firewall rules problem

Posted on 2014-04-22
4
416 Views
Last Modified: 2014-04-22
Hi everyone!

I have two astaro firewalls with a wireless bridge between them:

astaro 1 (site a):
eth0 --> LAN
eth1 --> PUBLIC
eth2 --> WIRELESS

astaro2 (site b):
eth0 --> LAN
eth1 --> PUBLIC
eth2 --> WIRELESS

I would like to let users in site a use the internet (and mail) from site b.

Which kind of rules / best procedure should I use?

Thanks!
0
Comment
Question by:ltpitt
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 16

Expert Comment

by:Shaik M. Sajid
ID: 40014316
that means u have internet at both sites..

if both firewalls are in same network then no issue just create internet user policy at site b.


if both firewalls are having different subnets then create a routing policy that internet will traffic will route through site B route.

allow site A users to access that route .. ins site B add users of site a in Internet users policy  ..

all the best
0
 
LVL 1

Author Comment

by:ltpitt
ID: 40014400
Hi there!

I'd need a bit more information to tackle this...

What do you mean by "on the same network"?

The astaros share the same network using the wireless eth interface.

I have, as default firewall on site a, the wireless bridge interface.
This way all my packets get on the wireless bridge way to site b.
Which kind of rule should I prepare on site b to allow users to get out?
Nat wireless interface to public?
0
 
LVL 16

Accepted Solution

by:
Shaik M. Sajid earned 500 total points
ID: 40014438
both sites are connected with wireless bridge.. .that means both sides same sub net working....


in your scenario all site A users should ping to the Site B firewall just create internet access policy for site A users on Site B firewall.

just the internet traffic will find it's way over site B firewall.

____________________________________

in case both sites sub nets are different then you have to create a routing on both firewalls to communicate each other. and site A lan traffic should be able top reach the site B firewall...

all the best.
0
 
LVL 1

Author Closing Comment

by:ltpitt
ID: 40014873
Adding a NAT rule for site a LAN on site b astaro did the trick: Thanks
0

Featured Post

2017 Webroot Threat Report

MSPs: Get the facts you need to protect your clients.
The 2017 Webroot Threat Report provides a uniquely insightful global view into the analysis and discoveries made by the Webroot® Threat Intelligence Platform to provide insights on key trends and risks as seen by our users.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I wrote this article to help simplify the process of combining multiple subnets. This can be used for route summarization also but there are other better ways to summarize routes, This article is a result of questions I participate in here at Ex…
AWS has developed and created its highly available global infrastructure allowing users to deploy and manage their estates all across the world through the use of the following geographical components   RegionsAvailability ZonesEdge Locations  Wh…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

732 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question