routing, iptables & nat

Phil Schaffner P.R.Schaffner at IEEE.org
Fri Jul 22 04:09:15 UTC 2005


On Thu, 2005-07-21 at 22:42 -0500, Bill McCormick wrote:
> Hello,
> 
> I want to use my FC3 box to control outcoing traffic but still use my 
> Netgear router as the main FW. How can I accomplish this?
> 
> My network (it's a home setup) is pretty basic and looks like this:
> 
> Internet <----> DSL Router (NG FVS318) <-----> LAN
> 
> The LAN is a a wired FC3 and some wired and wireless Windows machines. 
> Currently, all clients with IP greater than the FC3 must proxy through 
> squid et. al. on the FC3; the router blocks everything unless its from 
> FC3. The FVS318 forwards incomging http, imap-ssl, pop-ssl, and ssl to 
> the FC3.

Firestarter (http://www.fs-security.com/) works well for me on my home
network, as well as for a local secondary firewall on work boxes.
Haven't made much use of the outgoing traffic rules, but the capability
exists in the GUI - can be either "Permissive/blacklist" or
"Restrictive/whitelist".

Phil





More information about the fedora-list mailing list