[ previous ] [ next ] [ threads ]
 
 From:  Chris Buechler <cbuechler at gmail dot com>
 Cc:  m0n0wall at lists dot m0n0 dot ch
 Subject:  Re: [m0n0wall] interDMZ firewall?
 Date:  Fri, 6 Jan 2006 18:15:57 -0500
On 1/6/06, tech at adaptive dot net <tech at adaptive dot net> wrote:
> Ok consider this.
> ive got a cisco switch hanging off the monowall DMZ port
> on that cisco switch is a subnet of 25-50 computers within same /24 class c
>
> -if one of those computers is talking to another, does traffic even go to
> the monowall or does the cisco switch handle it all
>

doesn't touch m0n0wall.


> -if it does make it to the monowall, do firewall rules apply
>

no, since it doesn't touch it.


> -if not, how can i make it so?
>

VLAN's, trunking, and a /30 subnet for each host (breaking up the /24
into little bits).

here's something I wrote that's not quite done, but might help if you
want to find out more about VLAN's (I wrote it with my Cat2924 too, if
you have an IOS-based switch it should be helpful)
http://wiki.m0n0.ch/wikka.php?wakka=VLAN

-Chris