Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Implementing a transparent IPchains box

Thread Tools
 
Search this Thread
 
Old 23 August 2005, 08:46 PM
  #1  
Stueyb
Scooby Regular
Thread Starter
 
Stueyb's Avatar
 
Join Date: May 2002
Posts: 1,893
Likes: 0
Received 0 Likes on 0 Posts
Default Implementing a transparent IPchains box

Hi Guys n Gals,

Hopefully someone can help me here. I have a system at work that runs on IIS but our remote sales force need access to it. This machine sits in the core of our network on the internal lan, not the DMZ.

To try and secure it a bit (putting it on the DMZ is not fiesable) I want to put a box inbetween the FW1 box and server box to drop all traffic that is not from a certain series of MAC addresses. I know this isnt 100% but it will stop most of the crap and nastyness from getting to the box. Any guides on how to implement this transparently. I was thinking a freebsd box running a highly custom configuration of ipchains.

Cheers

Stu
Old 23 August 2005, 10:20 PM
  #2  
dsmith
Scooby Regular
 
dsmith's Avatar
 
Join Date: Mar 1999
Posts: 4,518
Likes: 0
Received 0 Likes on 0 Posts
Default

If your "filter" box is somehwhere between your "FW1" box (Firewall-1 i.e. your main internet firewall ?) and the server elsewhere on the corporate LAN. It will *only* see the mac address of the routers either side. MAC addresses dont propagate beyond the immediate LAN segment.

Would have thought you'd be better of with a proxy server on the DMZ that very carefully controls which URLs it will forward to the real server.
Old 24 August 2005, 02:16 AM
  #3  
stevencotton
Scooby Regular
 
stevencotton's Avatar
 
Join Date: Jan 2001
Location: behind twin turbos
Posts: 2,710
Likes: 0
Received 1 Like on 1 Post
Default

You wouldn't use ipchains anyway, iptables perhaps which has superceeded it, but if you want to use freebsd then ipchains isn't what you want, use a native freebsd option instead.

Saying that, dsmith is right. It's not the right way in that situation. If it has to be minus DMZ, I'd go for an SSL-enabled proxy with basic HTTP auth and forward requests to the server you want to give them access to. If the sales people only come on from certain IPs I'd also lock it down to that, MAC filtering isn't an option in that scenario.
Old 24 August 2005, 09:56 AM
  #4  
stevem2k
Scooby Regular
 
stevem2k's Avatar
 
Join Date: Sep 2001
Location: Kingston ( Surrey, not Jamaica )
Posts: 4,670
Likes: 0
Received 0 Likes on 0 Posts
Default

They're in sales ffs ... should be kept off the network completely .....
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Mattybr5@MB Developments
Full Cars Breaking For Spares
28
28 December 2015 11:07 PM
Mattybr5@MB Developments
Full Cars Breaking For Spares
12
18 November 2015 07:03 AM
gazzawrx
Non Car Related Items For sale
13
17 October 2015 06:51 PM
InTurbo
Other Marques
20
08 October 2015 08:59 PM
Ganz1983
Subaru
5
02 October 2015 09:22 AM



Quick Reply: Implementing a transparent IPchains box



All times are GMT +1. The time now is 10:32 PM.