On 18 Oct 2002, hans privat wrote:
> Reading the docs about DHCP shows a big disadvantage, if using a
> DHCP-server :
> the connected clients does NOT have some knowledge of the neighbourhouds
> of clients.
> to circumvent this problem, the docs talks about setting up a real DNS
> within the local network. and this DNS should NOT be the firewall.
> Now - I have 3 workstations and 1 (designated) firewall. and maybe, the
> workstations would be grow in the future.

Hans-

Is this for your home network?  If you are reading the Linux System 
Administrator Guid they are talking about not installing a firewall and 
DHCP on the same  machine in a large network.  If all you are trying to do 
is install a gateway and firewall for your home network I would suggest 
the following:

Open the Mdk Control Center and set up Internet Connection Sharing.  If 
you have two nic cards, have the one go to your wan and the other nic go 
to your local lan.  The wizard will set up DHCP and caching DNS.  As long 
as your ISP hands you an address when you connect on the wan, DNS will be 
available to the machines on your lan.   I have a machine at home that 
does this, my machines on the lan use the Mdk box as their dhcp, dns, 
gateway and squid.  Works very well and the performance is more reliable 
and faster than a LinkSys!

I have an 8.2 box doing this now, I can't get 9.0 to work correctly, but 
once I get my boxed version I will play with it some more.

-Scott








> 
> the result of all these docs just now is, that I am confuesed - does not
> know what I should do. 
> 
> would it be possible to give some helps in realizing these
> installation-steps ?
> 
> thanks once again
> bye hans
> 
> Am Don, 2002-10-17 um 21.41 schrieb Ron Stodden:
> > hans privat wrote:
> > > hi,
> > > in a sysadmin-book  I've read, that with kernel 2.4 the "iptables"
> > > should be used.
> > > 
> > > now I have done a lookup with lsmod and have seen, that there was NO
> > > iptables but an ipchains. 
> > 
> > You have the iptables RPM installed.  Good!  But you must now delete the 
> > ipchains ROPM - use kpackage to do that.
> > 
> > > then I have done a rmmod ipchains and was trying at first a modprobe
> > > iptables. the answer was " there is no iptables-modul",
> > > then I tried it again with insmod iptables, but got this here :
> > > [root@jojobaer /]# insmod iptables
> > > insmod: iptables: no module by that name found
> > 
> > Don't worry about this.  Leave the kernel modules to look after themselves.
> > > 
> > > Now I was looking with locate iptables and have found it in
> > > "/sbin/iptables".
> > > 
> > > Is there no module available, called "iptables" for mdk 8.2 ? 
> > 
> > No.
> > 
> > > and what is this prog "/sbin/iptables" ?
> > 
> > That is the guts of it.  You use this to install and maintain the 
> > iptables rules.
> > 
> > > how to use it ?
> > 
> > man iptables
> > 
> > > am sorry about my bloody questions, but have never done a job with
> > > masquerading and firewalls - so these are my first steps with it.
> > > right now I'm understanding only "moon" of about all these things. hope,
> > > anybody can help me here !!!!
> > 
> > A very simple way to get set up is to download to /etc/iptables the 
> > rc.iptables-2.3.8pre7 script from:
> > 
> > http://monmotha.mplug.org/firewall/index.php
> > 
> > cd to /etc/iptables, and customise it with an editor as explained in the 
> > script, then:
> > 
> > ./rc.firewall-2.3.8pre7
> >    -- to install or reinstall it,
> > iptables-save > /etc/sysconfig/iptables
> >    -- to save it from the kernel for auto reinstall after every boot
> > 
> > then you will have a nice firewall with masquerading, without even 
> > rebooting!
> > 
> > -- 
> > Ron. [Melbourne, Australia]
> >     troels... now updated to use sunet.se server.
> >     See:  http://members.optusnet.com.au/ronst/
> > 
> > 
> > 
> > 
> > 
> > 
> > ----
> > 
> 
> > Want to buy your Pack or Services from MandrakeSoft? 
> > Go to http://www.mandrakestore.com
> 
> 
> 
> 


Want to buy your Pack or Services from MandrakeSoft? 
Go to http://www.mandrakestore.com

Reply via email to