Koozali.org: home of the SME Server

Multihomed SME server installation (WAN/DMZ/LAN1/LAN2)

Offline arne

  • ****
  • 1,116
  • +0/-4
Multihomed SME server installation (WAN/DMZ/LAN1/LAN2)
« on: September 04, 2005, 04:31:05 AM »
WAN = Internet
DMZ - Network segment for aditional servers.
LAN1 - Wireless LAN
LAN2 - Cabeled LAN

- Firewall function between those 4 network segments.

Guess I basically can do the firewall part of it myself, but would like help with these tasks:

1. Testing of a SME server installation based om 4 (eventually 3) network adapters.

2. Development of some kind of interactive configuration tool (Web or shell based.)

Have done a bit simular things with Centos and Slackware, and guess it can be done with the SME server as well.

If anybody interested, please leave a msg .. :-)

Best reg Arne.
......

Offline arne

  • ****
  • 1,116
  • +0/-4
Multihomed SME server installation (WAN/DMZ/LAN1/LAN2)
« Reply #1 on: September 04, 2005, 10:40:12 AM »
It has been suggested. Why not also do it in such a way that the suggestions come true ? A 4 NIC installation should cover "it all" ??!!

http://forums.contribs.org/index.php?topic=28202.0
......

Offline arne

  • ****
  • 1,116
  • +0/-4
Multihomed SME server installation (WAN/DMZ/LAN1/LAN2)
« Reply #2 on: September 07, 2005, 02:48:14 AM »
No one interested ?

May be I did not present the idea the right way ??

Of cource you could have a lot of firewall experience, but the only "minimum qualifications" that is needed is to own a PC with 3 or 4 network adapters.

Instructions for installing aditional networkcards, configuring firewall(s) etc will be posted here.

The first thing that will have to be done is to check out if the sme server can be used, for this purpose, the practical way, by installing the network adapters. I guess it will, and then it is just to do the configuration part of it.

I think that a sme with a lan2 and a dmz can be used in many interesting ways. One way could be to add aditional server capasity while things grow or or for other reasons. To set up two sme servers in "series" or "tandem" so server functions can be changed between those two using a simple command could also be an option.

I think that the main need to make such a project will be somebody who have time and interest for the testing part of it.

Don't know how to take it from the iptables configuration script level to some more sophisticated interactive shell, but even though it should be only a configuration script option, it could still open up for some interesing use. (And if things is working ok, a interactive config shell could be a new project.)

Best reg Arne.
......