Re: LAN RAS setup guide?



Before I address this futher below,...keep in mind that the root cause is
due to you having a single subnet LAN that does not already have a LAN
Router making the Routing Decisions which leave your Firewall as the Default
Gateway of everything.

If you LAN was multi-segment with a LAN Router as the Default Gateway of
everything (meaning the firewall would not be such),...you would not even be
having this problem.

Now,...onward....

"Bill Kearney" <wkearney99@xxxxxxxxxxx> wrote in message
news:ysqdnYkCa5qpV9HUnZ2dnUVZ_gmdnZ2d@xxxxxxxxxxxxxxxx
The root of your problem is the two Internet connections. That is, I
mean, each LAN has its own.

No, not if I don't expect the devices on each segment to use the other
outbound gateway.

No, just the opposite, two routers as I described is what let's each side
use thier own internet connection instead of one side being forced to use
the "other side's" Internet connection,..which is what a single router
causes.

Think this illustration through. Your problem is the exact same situation
you would create if you had two Subnets on your lan with a single router
between them,...then tried to have each subnet with its own separate
firewall and internet connection. It just would not work like that because
both subnets would need to use the LAN Router as the Default Gateway which
is turn would use one of the Firewalls as its Default Gateway (leaving the
other firewall unused).

I just want the hosts to connect to each other.

Then it takes what I described. Although I have another suggestion below..

Two RAS boxes? That's a stupid waste of money.

That is a matter of opinion. If that is what the network structure
requires,..then that is what it requires.

However with modern Firewalls there is a new option if the Firewalls are
multi-interfaced (more than just 2). Many Firewalls have other interfaces
that can be used for additional "internal" segments or DMZ segments. If the
two firewalls involved can have an additional "internal" (that's internal,
not DMZ) on one of their other interfaces then you would connect the two
"extra" interfaces of the firewalls to each other and give it the "2-host"
IP Segment,..then establish a "routed" relationship (not a firewalled NAT)
between the real LAN segments and this one. It would look like this

[Internet] [Internet]
| |
<Firewall #1>---2-host link---<Firewall #2>
| |
[LAN #1] [LAN #2]


Now each LAN can use their own Firewall as their Default Gateway and it
works fine because the Firewall is pulling double-duty by acting as a LAN
Router and A Firewall at the same time. Notice with this that you **still**
have two router boxes involved :-),...it is just that you didn't have to
buy anything because something you already have in place is doing multiple
jobs.

Hope that makes sense...

--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------


.



Relevant Pages

  • Re: Network Hardware
    ... LAN With Two Routers" and now wonder whether or not to send this message as ... I was also hoping to use the DLink Router ... have to go through the router to get to the internet on the other subnet. ...
    (microsoft.public.windowsxp.network_web)
  • Re: Which home user router has a decent firewall inside it?
    ... Not for your LAN. ... The NAT translation on the router will ... NAT will inspect any packets if at all. ... public IP addresses in your LAN) and keep the firewall active. ...
    (comp.security.firewalls)
  • Re: Help on RRAS
    ... A router routes between subnets, so it doesn't work if both sides ... You will need to put the LAN machines in a different IP subnet from ... "link" segment (ie the segment which links the RRAS router to the ... Surely the firewall is ...
    (microsoft.public.windows.server.networking)
  • Re: Help on RRAS
    ... You will need to put the LAN machines in a different IP subnet from the ... "link" segment (ie the segment which links the RRAS router to the firewall). ...
    (microsoft.public.windows.server.networking)
  • Re: [SLE] DSL problem
    ... If the DSL modem ... assigned a valid external IP by the ISP and then route IPs in your subnet to ... the inet facing NIC in your firewall box or alternately to a hub/switch. ... private IPs on the lan to the internet. ...
    (SuSE)