[EMAIL PROTECTED] wrote:

I have a reason to explore a single nic route. That is multi-homing, external and internal interface on the same ethernet interface.

Assuming this can be done, I haven't even tested the
concept yet,
Are there glaring security reasons not to do this?

It can be done, but yes, there are glaring security reasons to avoid such a practice.

The primary issue is with both internal and external networks on the
same physical wire, it is trivial in the extreme to simply bypass the
router.  This makes the router either redundant (no need for it in the
first place, since everyone on the same wire can already talk amongst
themselves), or allows violation of any firewall rules you're trying to
implement on the router.

The only instance I can think of in which a single physical interface
router would make sense to me is if you're using VLANs, in which case
you could build a router to bridge different VLAN segments on a single
physical link.  Of course, I suspect if you're buying VLAN capable
switches, you probably wouldn't have posted the above question in the
first place.

There are some other instances where this sort of topology might be
useful, but in general you're better off to simply renumber your networks.

Provide a bit more detail about what you're trying to accomplish, and
the constraints you're working with (ie no money to buy two hubs, trying
to connect multiple existing networks that can't be renumberd to a
single physical segment, or whatever), and we can probably provide
decent advice.

--
Charles Steinkuehler
[EMAIL PROTECTED]





-------------------------------------------------------
This SF.net email is sponsored by: Etnus, makers of TotalView, The debugger for complex code. Debugging C/C++ programs can leave you feeling lost and disoriented. TotalView can help you find your way. Available on major UNIX and Linux platforms. Try it free. www.etnus.com
------------------------------------------------------------------------
leaf-user mailing list: [EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user
SR FAQ: http://leaf-project.org/pub/doc/docmanager/docid_1891.html

Reply via email to