Coexisting a modem/router and router/firewall.
Coexisting a modem/router and router/firewall.
Author
Discussion

JonRB

Original Poster:

80,068 posts

302 months

Saturday 23rd April 2005
quotequote all
Hi folks

I could do with a little advice on networky stuff.

I have a D-Link DSL-500 ADSL modem/router that has happily been serving my home hetwork as a modem, router and DHCP server, providing NAT, and feeding into a Netgear FS108 8-way switch. All fine and stable.
I also have a 5-way switch daisy-chained off that and a Linksys WAP54G Wireless Access Point, but that isn't really relevant.
My network clients have the router's fixed IP address set as the default gateway and all works well.

I've recently decided we need a proper SPI firewall and have bought a Linksys BEFSX41 to act as a bridging firewall between the modem and the switch.

Anyway, I'm a bit confused because there is obviously an overlap between the two devices - both provide routing, DHCP and NAT.

How should I configure them? Should I turn off all DHCP, NAT, etc. on the DSL-500 and set the BEFSX41's IP address as the DMZ address on the DSL-500, perhaps?
Or is there a way of keeping things pretty much as they are but configuring the firewall as a bridge?

What about IP addresses? Should I move the DSL-500's fixed IP address from 192.168.1.1 to another address and have the new firewall device as 192.168.1.1 (and hence the default gateway for the clients of the network) or should it stay as it is and the new firewall get a different IP address?

Sorry if the above is a really stupid question, it's just the overlap between the two devices and how they are meant to co-exist that is confusing me.

Thanks in advance
Jon






>>> Edited by JonRB on Saturday 23 April 22:24

agent006

12,058 posts

294 months

Saturday 23rd April 2005
quotequote all
JonRB said:
Should I turn off all DHCP, NAT, etc. on the DSL-500 and set the BEFSX41's IP address as the DMZ address on the DSL-500, perhaps?


Yes.

I'd run the modem-firewall network on a different subnet to the internal stuff. Say have your DSL-500 on a 192.168 address and your internal stuff on a 10.whatever address range.

JonRB

Original Poster:

80,068 posts

302 months

Monday 25th April 2005
quotequote all
I think I understand.

So I change the modem's IP address from 192.168.1.1 to, say, 192.168.2.1 and turn off all DHCP, NATting, etc.

I set the firewall's IP address to 192.168.1.1 and it becomes the default gateway for my network clients (so they don't need any re-configuring) and it takes over DHCP and routing.

I tell the firewall that its public IP address is 192.168.2.2 and I set the modem to forward all traffic to 192.168.2.2 (possibly by using the DMZ setting on the modem which allows me to specify one DMZ IP address).

Is that right?

>> Edited by JonRB on Monday 25th April 17:06

JonRB

Original Poster:

80,068 posts

302 months

Monday 25th April 2005
quotequote all
Well, I came close to having things working.

I changed the modem's IP address to 192.168.2.1 and turned off NAT, DHCP, etc. and it connected to my ISP as usual and was happy.

I set the firewall's WAN IP address to 192.168.2.2 with a default gateway of 192.168.2.1, its LAN IP address to 192.168.1.1 and set up DHCP.

My PC was able to connect to 192.168.2.1 and remote administer the modem and to 192.168.1.1 and remote administer the firewall.
All the network clients (including my PC) picked up new IP addresses from the new DHCP server fine (I set a different range in the 192.168.1.* subnet so I could verify this) and were able to see each other. So far so good.

The only problem is connecting the modem and the firewall. I tried leaving NAT on and setting the DMZ port to 192.168.2.2 but that didn't seem to work.

I think I need to set up a static route on the modem. I tried 192.168.2.2 with a default gateway of 192.168.2.1 but it said that duplicates weren't allowed, which confused me.

I feel like I'm really close. Can someone give me the final piece of the jigsaw?
Agent006? Plotless? Marshy? Anyone?

>> Edited by JonRB on Monday 25th April 21:34

JonRB

Original Poster:

80,068 posts

302 months

Tuesday 26th April 2005
quotequote all
For those that are interested (which judging by the number of replies here is virtually nobody) I've got it working.

I changed the IP address of the modem to 192.168.10.1 and let it continue to be a DHCP server with available addresses of 192.168.10.2 onwards and with NAT left on. In fact, pretty much unchanged from its current (known good) settings apart from the IP address changes.

I set the WAN ip address of the firewall to DHCP client, which immediately picked up an address of 192.168.10.2 from the modem's DHCP server.
I set up the LAN IP address of the firewall to 192.168.1.1 and set its DHCP server to be the settings the modem used to have.

Everything now works fine.

>> Edited by JonRB on Wednesday 27th April 10:21