On Sat, Aug 8, 2009 at 5:24 PM, Tom Furie <[email protected]> wrote:

> On Thu, Aug 06, 2009 at 01:18:09PM +0200, Jack Knowlton wrote:
>
> > Right :D
> >                                             {server4}
> >                                                 |
> >
> {ISP}--{DSL-brige}--(eth0)-{Debian}-(eth1)--{Switch}-(eth0)-{server2}-(eth1)
> >                               |                 |                      |
> >                            (eth2)             (eth0)-{server3}-(eth1)  |
> >                               |                                   |    |
> >                               \---------{switch2}----------------/----/
> >                                             |
> >                                            {AP}
> >
>
> Why do you have multiple interfaces on Servers 2 and 3? Wouldn't a
> setup something like the following be easier to manage?
>
>  {ISP}
>   |
> {Debian}-{Switch}
>   |        |
>  {AP}      +-{Server2}
>            |
>            +-{Server3}
>            |
>            +-{Server4}
>
> Cheers,
> Tom
>

Agreed. Always work with KISS. Building it is only a very small part of the
overall process and you'll want to be able to make changes to your setup at
some point. Having a good mental "map" of your setup will greatly reduce
stress when the time comes.

My advice.

Setup your router as follows.

Router
INET0
ETH1(routing no NATing)
ETH2(NATing with a DHCP server that points to this iface)

DHCP will tell your "unknown" clients that they need to access the inet via
ETH2. While your known clients will simply have ETH1 as their default gw.

In theory you wouldn't even need "eth2" to be a physical card....but..it's
probably wise with wifi and "servers".


Depending on your setup..and who the wifi users are..you may want to
consider using squid..but...there is a razor fine line between simple and
painful if your new to proxy use.




>
> --
> On the night before her family moved from Kansas to California, the little
> girl knelt by her bed to say her prayers.  "God bless Mommy and Daddy and
> Keith and Kim," she said.  As she began to get up, she quickly added, "Oh,
> and God, this is goodbye.  We're moving to Hollywood."
>
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.9 (GNU/Linux)
>
> iEYEARECAAYFAkp97SIACgkQ2svup27rrImLsgCgsASOifCGCAeWLwUFrezLQsj5
> sYMAoMnB0ZFMKpAb1r0TWBBE5cyTwai8
> =sDy/
> -----END PGP SIGNATURE-----
>
>


-- 
Grass is always greener at the other side isn't it? Maybe that's because it
rains more there.

Reply via email to