Secure subnets and bandwidth control

Secure subnets and bandwidth control

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Secure subnets and bandwidth control petersson 10-26-2005
Posted by on October 26, 2005, 2:26 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Ng,

This is my situation:

In my office building we have an incoming fiber with 3 fixed IP
addresses from our ISP. We have 3 offices that need 'secure' networks.
The different offices should not be able to browse each others
networks. Furthermore, I need to restrict the bandwidth on each
network. I want office 1 to have 2 mb/sec, office 2 to have 1 mb/se
etc.

Any suggestions on products, techniques, how-to's, resources etc.

At present, only one office is connected (with linux IPcop as
firewall/router). Like this:

|
|
ISP
|
|
IPcop
|
|
office_1

Do I need one 'master' router with bandwidth restriction capabilities
on top of five subnet routers/switches? Sounds bizarre to me, but I'm
only a newbie... Like this:

|
ISP
|
---MASTER_router----
| | |
SUB SUB SUB
router1 router2 router3
| | |
office1 office2 office3

There must be some all-in-one box that does this?



Posted by Moe Trin on October 26, 2005, 2:53 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
In the Usenet newsgroup comp.security.firewalls, in article
petersson@my-deja.com wrote:

>In my office building we have an incoming fiber with 3 fixed IP
>addresses from our ISP. We have 3 offices that need 'secure' networks.

Are these like three separate companies, and you are the landlord?

>The different offices should not be able to browse each others
>networks.

Any firewall can do that

>Furthermore, I need to restrict the bandwidth on each network. I want
>office 1 to have 2 mb/sec, office 2 to have 1 mb/se etc.

That's possible - the terms are 'rate limiting' or 'throttling'

>Any suggestions on products, techniques, how-to's, resources etc.

http://ibiblio.org/pub/linux/docs/HOWTO/
http://en.tldp.org/HOWTO/HOWTO-INDEX/howtos.html

-rw-rw-r-- 1 gferg ldp 297491 Sep 4 2003 Adv-Routing-HOWTO

>Do I need one 'master' router with bandwidth restriction capabilities
>on top of five subnet routers/switches? Sounds bizarre to me, but I'm
>only a newbie...

http://tldp.org/guides.html
2. Linux Consultants Guide
http://tldp.org/LDP/lcg/html/index.html

That guide lists 30 companies in Sweden who will be happy to set this up.

> |
> ISP
> |
> ---MASTER_router----
> | | |
> SUB SUB SUB
>router1 router2 router3
> | | |
>office1 office2 office3

|
ISP
|
Interface 1
*nix box of some kind
NIC 1 NIC 2 NIC 3
| | |
office1 office2 office3

>There must be some all-in-one box that does this?

Sure - ask the consultant.

Old guy


Posted by Volker Birk on October 30, 2005, 1:39 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
petersson@my-deja.com wrote:
> In my office building we have an incoming fiber with 3 fixed IP
> addresses from our ISP. We have 3 offices that need 'secure' networks.
> The different offices should not be able to browse each others
> networks.

Implement a zone concept, i.e. the classical three zone concept will
do. Implement the DMZ as an encrypted VPN.

> Furthermore, I need to restrict the bandwidth on each
> network. I want office 1 to have 2 mb/sec, office 2 to have 1 mb/se
> etc.

This is not a security related topic. Please ask about traffic shaping
in an appropriate group.

Yours,
VB.
--
"Ich bin ein freier Mensch und werde jetzt von meinen Freiheitsrechten
Gebrauch machen - und zwar ausgiebig - natürlich nur in dem Rahmen, den
Otto Schily mir noch zur Verfügung stellt."
Wolfgang Clement am 10.10.05 als Noch-Superminister


Similar ThreadsPosted
Blocking foreign subnets April 12, 2005, 4:01 pm
Multiple Subnets with Sonicwall May 9, 2008, 5:30 pm
VPN with conflicting subnets with Netscreen-50 and ZyWALL 70 June 14, 2006, 6:11 am
Help, Hardware Firewall that will control outgoing program control December 2, 2006, 8:17 pm
Secure Auditor new release and Secure your database with Secure Auditor April 14, 2008, 5:15 am
Secure Auditor new release and Secure your database with Secure Auditor April 14, 2008, 5:16 am
bandwidth distribution December 5, 2005, 8:41 pm
Pix 520 - Can it log bandwidth usage? January 5, 2006, 10:44 am
limiting bandwidth per program July 30, 2005, 8:42 pm
Network bandwidth stealing December 31, 2007, 3:55 am

The site map in XML format XML site map

Contact Us | Privacy Policy