Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 





Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Networking Forum > Networking Support
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read

Networking Support General Networking Support Forum

Reply
 
Thread Tools
Old 07-22-2008, 07:11 PM   #1 (permalink)
Registered User
 
Join Date: Jul 2008
Posts: 2
OS: xp


network design - advise needed

Hi!

I am trying to setup a network here and I am quite stumped. Will appreciate any help you can offer. Thank you!

What I have:
- unmanaged switch
- firewall (with a router)
- 2 web servers
- a class C network assigned by ISP (let's say 10.10.10.0)

What I need:
- connect web servers to the Internet (must have external IPs)
- protect the servers by firewall (close all ports except ftp, smtp, http, bind)
- connect the web servers into a local network

So far I have connected the web servers to the switch and the switch to the uplink. It works! But how do I introduce the firewall? If I add it between the switch and the uplink the servers won't have the external IPs anymore :(
anton1980 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 07-22-2008, 08:23 PM   #2 (permalink)
Tech Hardware Team
 
lazareth1's Avatar
 
Join Date: Jan 2005
Location: Hong Kong, previously Fife in Bonnie Scotland
Posts: 1,046
OS: Vista SP1, Ultimate

My System

Re: network design - advise needed

Whats the make and model of everything you have there on the list?
__________________

"Nothing is True, Everything is Permitted"
JAFFA KREE!!
Peace Through Power!!
lazareth1 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 07-23-2008, 06:38 AM   #3 (permalink)
Registered User
 
Join Date: Jul 2008
Posts: 2
OS: xp


Re: network design - advise needed

hi!

switch: Cisco Catalyst Express 500
firewall: Cisco ASA 5505

i already got advised on another forum to put the firewall between the uplink and the switch and then create a local network for the severs, using NAT.
anton1980 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 07-23-2008, 06:41 AM   #4 (permalink)
af3
TSF Enthusiast
 
af3's Avatar
 
Join Date: Jun 2008
Location: USA
Posts: 757
OS: Windows XP SP3

My System

Re: network design - advise needed

This sounds like a test question.
__________________
You are currently using 0 MB (0%) of your 7171 MB, what's wrong with you?
af3 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 07-24-2008, 02:38 AM   #5 (permalink)
Tech Hardware Team
 
lazareth1's Avatar
 
Join Date: Jan 2005
Location: Hong Kong, previously Fife in Bonnie Scotland
Posts: 1,046
OS: Vista SP1, Ultimate

My System

Re: network design - advise needed

They're right about connecting it in between the switch and the uplink, but as you said using NAT etc means you would not use the external IP addresses for the servers.

I would use a PIX firewall without the routing function so your webservers could use the public IP addresses.
__________________

"Nothing is True, Everything is Permitted"
JAFFA KREE!!
Peace Through Power!!
lazareth1 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 07-25-2008, 06:48 AM   #6 (permalink)
af3
TSF Enthusiast
 
af3's Avatar
 
Join Date: Jun 2008
Location: USA
Posts: 757
OS: Windows XP SP3

My System

Re: network design - advise needed

Is there such a notion in a router (maybe commercial grade) of two or more servers using the same port, and using cross-server communication to determine which server should reply to the request? I am just curious! :)
__________________
You are currently using 0 MB (0%) of your 7171 MB, what's wrong with you?
af3 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 07-27-2008, 08:01 PM   #7 (permalink)
Tech Hardware Team
 
lazareth1's Avatar
 
Join Date: Jan 2005
Location: Hong Kong, previously Fife in Bonnie Scotland
Posts: 1,046
OS: Vista SP1, Ultimate

My System

Re: network design - advise needed

Quote:
Originally Posted by af3 View Post
Is there such a notion in a router (maybe commercial grade) of two or more servers using the same port, and using cross-server communication to determine which server should reply to the request? I am just curious! :)
Wll If ya wanted to make a server replay to a specific request you would use port forwarding setup on the router to forward certain requests to the server via it's IP address. I'm not quite sure what you mean by your cross over scenario, but it seems more complicated than doing what I just stated.
__________________

"Nothing is True, Everything is Permitted"
JAFFA KREE!!
Peace Through Power!!
lazareth1 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 07-27-2008, 09:36 PM   #8 (permalink)
Registered User
 
Join Date: Jul 2008
Location: Indonesia
Posts: 128
OS: vista


Re: network design - advise needed

Cisco CE 500 switches are managed switches dude, they only use web config and not console style config.
What module you have in the ASA? if you have the additional 4 ports ethernet module you can just plug the servers right to the ASA and make them part of the DMZ.
If you don't, just make VLAN for servers only and configure the VLAN on both the ASA and the switch.

You can do it like this:

router ----> ASA -----> switch -----> workstation
-----> servers

or like this:

router -----> ASA -----> switch -----> workstation
-----> servers
krishananda is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -7. The time now is 07:33 AM.



Copyright 2001 - 2008, Tech Support Forum

Search Engine Friendly URLs by vBSEO

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82