Click to See Complete Forum and Search --> : how to seperate a pc form the network.


jailbreaker
01-01-2006, 08:27 PM
Hey Happy New Year to all :)

I'm not sure if there is a better way to do this.

what I want to do is seperate my FTP server from the rest of my network with a firewall like smoothwall or someother "easy to use" software (im not afreaid of the CLI), and have an IDS like snort and block all other ports on the FTP so only FTP traffic an pass through.

im not sure if I explained my self right but I hope you kind of understand what I want to do.

knute
01-01-2006, 10:21 PM
You'd put your ftp server into the DMZ and then alter your rules to that machine from there.

Smoothwall is a good choice to do something like that with.

Actually, I think that the smoothwall website has an example sorta like what you describe.

HTH

jailbreaker
01-02-2006, 12:15 AM
well I installed smoothwall and I can ping everything inside the network but I cant ping an outside source like google.

knute
01-02-2006, 12:24 AM
Doh! I have no clue about smoothwall, shorewall is what I've used before.
It has sample configs and such.

http://www.shorewall.net/

gtmtnbiker98
01-02-2006, 11:58 PM
To do a DMZ setup, you would need a third NIC on the Shorewall box.

knute
01-03-2006, 12:14 PM
LOL True. I had forgotten that I had 3 nics in the box that I was using when I set it up.

Another way, would be to set up the firewall on the fileserver to allow only ftp.