amahi as router 2 nics

wtalking
Posts: 10
Joined: Sat Jan 03, 2009 10:58 am

amahi as router 2 nics

Postby wtalking » Sat Jan 03, 2009 11:04 am

hello all first time post on the new forum.

My question is has anyone tried eliminating their router all together by installing 2 nics and just using a switch. I do not have much experience with fedora. all of my other systems are debian based.
I would like to have one nic pointed toward my cable modem dynamic ip and the other nic pointed toward my network. I was thinking of using firestarter but need a little help with the network config side of things in fedora 9

I didnt see any other posts on the topic and thought a discussion may be helpful to others

thanks

gjc1000
Pro User
Pro User
Posts: 133
Joined: Sat Jan 03, 2009 8:30 am

Re: amahi as router 2 nics

Postby gjc1000 » Sat Jan 10, 2009 7:33 pm

I'd like to know that too
gjc1000
Chi pecora si fa, il lupo se la mangia.

User avatar
cpg
Administrator
Posts: 2618
Joined: Wed Dec 03, 2008 7:40 am
Contact:

Re: amahi as router 2 nics

Postby cpg » Sat Jan 10, 2009 8:25 pm

this can be done, and it has been done, however, it's not the supported configuration out of the box.

a small mistake can render your data open to the internet. keep that in mind!

here is what you need to do:

- make sure eth0 is on the LAN side (your network). this is important for amahi to work
- hence eth1 is handling the WAN wide of things
- make sure you run a firewall in eth1!!!

some people recommend shorewall, moonwall, or others.

report back how it works for you! :)
My HDA: Intel(R) Core(TM) i5-3570K CPU @ 3.40GHz on MSI board, 8GB RAM, 1TBx2+3TBx1

User avatar
rgmhtt
Posts: 421
Joined: Sun Jan 11, 2009 9:26 am

Re: amahi as router 2 nics

Postby rgmhtt » Tue Mar 17, 2009 7:08 am

At one point I wanted to do this too. Then I thought REAL HARD. I AM a security Xpert...

Why would I ever what my SMB/NFS server so exposed? One misstep and I am DEAD! And a basic gateway/firewall is pretty cheap.

I DO run a Linux router/gateway, because I have native IPv6 here, and decent boxes are still expensive. So I am even more aware of why I do not want to do this.

Finally the only real justification I can see for this is running Amahi as a HTTP proxy and/or PBX.

For the HTTP proxy, so you route in and out of Amahi's one interface. Not hard to do.

For the PBX, it makes sense to put the phones on their own network.

Again, my security background colors my opinion. Don't go this way, even if you are an expert.

User avatar
moredruid
Expert
Posts: 791
Joined: Tue Jan 20, 2009 1:33 am
Location: Netherlands
Contact:

Re: amahi as router 2 nics

Postby moredruid » Tue Mar 17, 2009 12:32 pm

I second rgmhtt's opinion. You don't want to do this. 1 mistake can cost you all your data.
especially if you want to use your hda as a webserver for a forum or blog for friends, that code can also contain bugs or be compromised. Once a hacker/bot *&%$ up your database Amahi will grind to a halt. Or worse: they go through that database and see how your network is set up, what shares you have, the usernames etc. and they steal your stuff or put trojans in executables. Yes it can happen. scripted attacks cost almost no effort and if you don't have proper countermeasures in place an attack can go on for hours/days without you noticing it. and once they're in, your data is toast.

If all your other boxes are debian: set 1 up as gateway for routing/firewalling and if needed web services (http/pop/smtp), but even then it's best to proxy those as well. the easiest way to really achieve that may be through a VM which you can lock down (read only, hah, try hacking that), make a snapshot of a good secure copy first and replace copy when in doubt)
echo '16i[q]sa[ln0=aln100%Pln100/snlbx]sbA0D2173656C7572206968616D41snlbxq' | dc
Galileo - HP Proliant ML110 G6 quad core Xeon 2.4GHz, 4GB RAM, 2x750GB RAID1 + 2x1TB RAID1 HDD

Lincee
Posts: 73
Joined: Sat Jul 04, 2009 3:34 pm
Location: Arnhem, NL
Contact:

Re: amahi as router 2 nics

Postby Lincee » Sat Aug 08, 2009 12:34 pm

I second rgmhtt's opinion. You don't want to do this. 1 mistake can cost you all your data.
especially if you want to use your hda as a webserver for a forum or blog for friends, that code can also contain bugs or be compromised. Once a hacker/bot *&%$ up your database Amahi will grind to a halt. Or worse: they go through that database and see how your network is set up, what shares you have, the usernames etc. and they steal your stuff or put trojans in executables. Yes it can happen. scripted attacks cost almost no effort and if you don't have proper countermeasures in place an attack can go on for hours/days without you noticing it. and once they're in, your data is toast.

If all your other boxes are debian: set 1 up as gateway for routing/firewalling and if needed web services (http/pop/smtp), but even then it's best to proxy those as well. the easiest way to really achieve that may be through a VM which you can lock down (read only, hah, try hacking that), make a snapshot of a good secure copy first and replace copy when in doubt)
i personally want to replace my router, so what i plan to do is install fedora, run a firewall on the WAN site, and disable all services to it.
would this be possible? to make amahi only on listen to the "inside" ?
LANTEA: Amahi 7 (vm), HP Proliant Microserver, 8GB RAM, 2x 1TB HDD, 1GB eth

User avatar
cpg
Administrator
Posts: 2618
Joined: Wed Dec 03, 2008 7:40 am
Contact:

Re: amahi as router 2 nics

Postby cpg » Sat Aug 08, 2009 12:41 pm

this is doable. here is the recommendation:

- use eth0 for the inside (lan)
- use eth1 for the outside (wan)

run the firewall on eth1, of course.

we have a router/firewall control module now. so whatever firewall you chose, we can probably make a module in a relatively short time to get it controlled from the networking tab in your hda.
My HDA: Intel(R) Core(TM) i5-3570K CPU @ 3.40GHz on MSI board, 8GB RAM, 1TBx2+3TBx1

billyprefect
Posts: 6
Joined: Wed Aug 11, 2010 1:57 pm

Re: amahi as router 2 nics

Postby billyprefect » Sat Jan 22, 2011 3:35 pm

Is this still doable?

I will find out in about 20 minutes I suppose.

horstt
Posts: 1
Joined: Mon Jul 18, 2011 9:26 pm

Re: amahi as router 2 nics

Postby horstt » Mon Jul 18, 2011 9:36 pm

Trying this myself, but since I'm a Linux n00b, I'm having trouble getting Fedora to do the routing bit.

I managed to add a second NIC (eth1), to which I want to connect my modem. I've tried following a guide to set up internet sharing. To summarize this:
I didn't change settings for eth0, since the DHCP server thing was working well. I configured eth1 to use DHCP. Then I did the internet sharing routine:
System --> Preferences --> Network Connections --> Add --> In the 'Wired' tab I filled in the MAC of the eth0 card --> in the IPv4 Settings tab I selected 'Share to other computers' ).
I connected my working PC to my eth0 card, and my modem to the eth1 card. I can now use internet on my HDA, and my PC is getting a DHCP address from my HDA (gateway 192.168.1.1, DHCP 192.168.1.50, DNS 192.168.1.50), but internet is not working on my working PC. I tried using 192.168.1.50 as a gateway, and manually entering some DNS addresses (openDNS), but to no avail.

I'm probably doing a simple thing wrong, but I cannot find it...

Who is online

Users browsing this forum: No registered users and 43 guests