On Mon November 14 2005 21:18, D Bhardwaj wrote: > So I decided to take a break from the server stuff and instead do a brick > and mortar firewall. So, message is try IPCop, it is too simple. > I install it, suddenly to be confronted with what looks like a colour coded > boxing match. In the green corner all is safe so put a server there, stay > away from the red corner, the blue is for wireless and orange for your web > server. Simple, but now be prepared to find upto 4 NICS! Do I have that > many slots? Different nics, either with drivers or which probe can detect. > Configure with static IPs, disconnect from the 'net. Do I need blue? Can > orange and green go together? Why did I get rid of those old nics, maybe I > have some old 10mbit ISA somewhere. Will they work? >
ISA cards will work if the modules are available for them. I use a 10Mb 3-Com ISA card in my IPCop Firewall. As far as the different zones, if you don't have wireless you will not need a blue zone. You will only need an orange zone if you have servers that have access to the internet, ie web servers is something that pops in my mind. There may be other services to put on the orange zone. The orange zone is there to have a buffer to your green zone (or internal network) but still allow a restricted interface to the internet. If you have nothing that is required to accept connections from the internet, then you would probably not need the orange zone. It is easier to use different cards, but ou can use the same type or model of cards for any of your zones. You just need to be able to identify which card is which for your connections or zones. One way to do this is to record the MAC address off of each card and physically know which card is in which slot according to MAC address. I do this by labeling the cards with A,B,C, etc and write down the corresponding MAC Address on a piece of paper. Once your setup is done, ifconfig your IPCop box to see which card IPCop assigned to which zone. Connect your cables accordingly. If you are setting up a blue zone, Kin wrote up a description of the steps in his blog on the CLUG web site. Hope that helps. Neil -- Neil Bower CLUG - http://clug.ca Registered Linux User # 323470 ( http://counter.li.org )
pgp8I3HWn11Fq.pgp
Description: PGP signature
_______________________________________________ clug-talk mailing list [email protected] http://clug.ca/mailman/listinfo/clug-talk_clug.ca Mailing List Guidelines (http://clug.ca/ml_guidelines.php) **Please remove these lines when replying

