Routing between subnets with a twist

Tech-Archive recommends: Fix windows errors by optimizing your registry



Right now I have a DHCP server set up on my SBS 2003 (SP2) machine.
It doles out our dns servers, gateway and time server to a 10.0.0.x
subnet.

The problem here is I probably have 20 machines that have no business
being on the internet. So I want to toss them on a separate subnet
for this and some other reasons. But if I set these machines
gateway's to 10.0.1.1 and have RRAS properly configured and the
gateway on the SBS 2003 machine is set to 10.0.0.1 (internet gateway)
on both NIC interfaces they'll still have internet access, right? And
even if I set the GW on the 10.0.0.x NIC up, but not on the 10.0.1.x
NIC they'll still find their way to the internet because of the
routing, I'm assuming.

How can I prevent one subnet from getting to the internet? This
second subnet will NOT be on a DHCP configuration, because the
machines in it hook up to analytical equipment that is picky about the
IP ranges they use. But I need the machines to be able to interact
with machines on the 10.0.0.x subnet.

Does that make sense?

In short 10.0.0.x - Internet OK
10.0.1.x - No internet but talk to 10.0.0.x

I could probably do this with a group policy by adding a separate OU
and putting those machines in it with no gateway address in a GPO..
but for those that need a gateway address if I ever have to change it
there's that 22-23 hour lag before the GPO auto updates that would be
troublesome.

.



Relevant Pages

  • Re: Routing between subnets with a twist
    ... It doles out our dns servers, gateway and time server to a 10.0.0.x ... The problem here is I probably have 20 machines that have no business ... So I want to toss them on a separate subnet ... gateway on the SBS 2003 machine is set to 10.0.0.1 (internet gateway) ...
    (microsoft.public.windows.server.sbs)
  • Thanks, and more info
    ... I uninstalled Norton Internet Security 2004, ... the network connection was restored. ... Chuck - you asked for the settings for both machines, ... Computer_1 (ICS Gateway, desktop, previously unpingable) ...
    (microsoft.public.windowsxp.network_web)
  • Re: HOWTO Ping LAN???
    ... and tunnel to other internal machines ... Port forward connections from the Internet "thru" ... |>network is by tunneling. ... |>from the outside to my default gateway and have the gateway ...
    (freebsd-questions)
  • Re: More Peer 2 Peer Troubles
    ... but No I only have one gateway in use in the NIC ... Only the Host has been connected to the ... Clientto the internet so as to directly link with the internet mainly ... all machines, not just the host. ...
    (microsoft.public.windowsxp.network_web)
  • Re: RRAS twin NIC and routing to default gateway
    ... so these machines should already be connected to the Internet. ... What default gateway setting do the machines with 50.x.x.x IP addresses ... If I remove RRAS I get the connectivity back again. ...
    (microsoft.public.windows.server.networking)