Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Implementing a transparent IPchains box

Thread Tools
 
Search this Thread
 
Old 23 August 2005 | 09:46 PM
  #1  
Stueyb's Avatar
Stueyb
Thread Starter
Scooby Regular
 
Joined: May 2002
Posts: 1,893
Likes: 0
Default Implementing a transparent IPchains box

Hi Guys n Gals,

Hopefully someone can help me here. I have a system at work that runs on IIS but our remote sales force need access to it. This machine sits in the core of our network on the internal lan, not the DMZ.

To try and secure it a bit (putting it on the DMZ is not fiesable) I want to put a box inbetween the FW1 box and server box to drop all traffic that is not from a certain series of MAC addresses. I know this isnt 100% but it will stop most of the crap and nastyness from getting to the box. Any guides on how to implement this transparently. I was thinking a freebsd box running a highly custom configuration of ipchains.

Cheers

Stu
Old 23 August 2005 | 11:20 PM
  #2  
dsmith's Avatar
dsmith
Scooby Regular
 
Joined: Mar 1999
Posts: 4,518
Likes: 0
Default

If your "filter" box is somehwhere between your "FW1" box (Firewall-1 i.e. your main internet firewall ?) and the server elsewhere on the corporate LAN. It will *only* see the mac address of the routers either side. MAC addresses dont propagate beyond the immediate LAN segment.

Would have thought you'd be better of with a proxy server on the DMZ that very carefully controls which URLs it will forward to the real server.
Old 24 August 2005 | 03:16 AM
  #3  
stevencotton's Avatar
stevencotton
Scooby Regular
 
Joined: Jan 2001
Posts: 2,710
Likes: 1
From: behind twin turbos
Default

You wouldn't use ipchains anyway, iptables perhaps which has superceeded it, but if you want to use freebsd then ipchains isn't what you want, use a native freebsd option instead.

Saying that, dsmith is right. It's not the right way in that situation. If it has to be minus DMZ, I'd go for an SSL-enabled proxy with basic HTTP auth and forward requests to the server you want to give them access to. If the sales people only come on from certain IPs I'd also lock it down to that, MAC filtering isn't an option in that scenario.
Old 24 August 2005 | 10:56 AM
  #4  
stevem2k's Avatar
stevem2k
Scooby Regular
 
Joined: Sep 2001
Posts: 4,670
Likes: 0
From: Kingston ( Surrey, not Jamaica )
Default

They're in sales ffs ... should be kept off the network completely .....
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Mattybr5@MB Developments
Full Cars Breaking For Spares
28
29 December 2015 12:07 AM
Mattybr5@MB Developments
Full Cars Breaking For Spares
12
18 November 2015 08:03 AM
gazzawrx
Non Car Related Items For sale
13
17 October 2015 07:51 PM
InTurbo
Other Marques
20
08 October 2015 09:59 PM
Ganz1983
Subaru
5
02 October 2015 10:22 AM




All times are GMT +1. The time now is 05:16 PM.