What you are seeing is the flexibility of IPCop.  You do not need 4 nics and 4 
zones (red, green, blue, orange) for a basic system.  But they might make 
sense in a more elaborate area.

The zones are relatively easy to define - they help identify the purpose of 
that connection:
Red - External Internet - anything that can arrive at the firewall from 
OUTSIDE the network you are protecting.
Green - The internal network.
Orange - Used if you want to set up a second IP Segment - usually for a DMZ.  
IPCop can route between the red, green, and orange.
Blue - for connecting wireless devices to the internal network, yet allowing 
control of what ports they can access.

How complex you set up your IPCop server depends on your needs.  Most people 
can get by with only red and green zones.  Anything else is a matter of 
opinion and paranoia.  (i.e. using an orange zone or DMZ for public servers 
is a good security measure and recommended, but is not a necessity.)

As for the NICs, you need one interface for each of the zones you are going to 
use.  They *should* be differnent brands/chipsets, so that you don't have to 
mess around with assigning IRQs and Memory addresses.  If you use different 
cards, IPCop will usually auto detect them for you.

During the install, it will detect a network card, and will automagically 
assign this card to the green interface.  This is a good thing - otherwise 
you couldn't connect to the box from the internal network.  Then later in the 
install process you are given the option to select the zones you want to use 
(Red-Green, Red-Orange-Green, etc.), and probe for another network card.  
Once the other card is connected, you are given a choice which remaining 
zones to assign the card to.  If you use only Red-Green, then this becomes 
very simple.

Unfortunately, installing a router like this suggests one have some background 
knowledge of IP routing.  You can get by without it, but it does help in 
getting things running.  (I'm not quite sure how comfortable you are with 
routing, so apologies if I'm stating something obvious).

The nice thing about IPCop is that it is such a fast install, you can try it 
out a few times and try different things each time through, then settle on 
the final configuration with what you've learned from the trials.  I can 
usually rebuild my IPCop box in about 15 or 20 minutes, including resetting 
my routing rules through the web interface....

HTH

Shawn

On Monday 14 November 2005 21:18, D Bhardwaj wrote:
> So I decided to take a break from the server stuff and instead do a brick
> and mortar firewall. So, message is try IPCop, it is too simple.
> I install it, suddenly to be confronted with what looks like a colour coded
> boxing match. In the green corner all is safe so put a server there, stay
> away from the red corner, the blue is for wireless and orange for your web
> server. Simple, but now be prepared to find upto 4 NICS! Do I have that
> many slots? Different nics, either with drivers or which probe can detect.
> Configure with static IPs, disconnect from the 'net. Do I need blue? Can
> orange and green go together? Why did I get rid of those old nics, maybe I
> have some old 10mbit ISA somewhere. Will they work?
>
> Is this normal? Do others have the same experience?
>
> Dharam
>
>
>
> _______________________________________________
> clug-talk mailing list
> [email protected]
> http://clug.ca/mailman/listinfo/clug-talk_clug.ca
> Mailing List Guidelines (http://clug.ca/ml_guidelines.php)
> **Please remove these lines when replying

Attachment: pgpHJKB3qFyMl.pgp
Description: PGP signature

_______________________________________________
clug-talk mailing list
[email protected]
http://clug.ca/mailman/listinfo/clug-talk_clug.ca
Mailing List Guidelines (http://clug.ca/ml_guidelines.php)
**Please remove these lines when replying

Reply via email to