Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > Router with both public and private connections - how to secure?

Reply
Thread Tools

Router with both public and private connections - how to secure?

 
 
Bob
Guest
Posts: n/a
 
      01-12-2005
I have a router that I need to install (and its required I use a
single router) with both a private link to the rest of my network as
well as a public Internet link. I'll take one serial to an Ethernet
port for the private into my LAN, and the other serial with a public
IP range to a different Ethernet port on the same router. That in
turn will go to a firewall, then back to my Corporate LAN for Internet
access.

S0/0 --> F0/0 --> Internal LAN (RFC1918 space mostly)
S0/1 --> F0/1 --> Public Internet (public routable IP's)

The point of concern is basically within the router. Are there
examples somewhere that can show how I can secure the router so the
internal IP range doesn't meet the external IP range? I want to plug
the hole with the best ACL and policy routing configuration I can
find. I can't have hackers find their way into my LAN through the
Internet from this router.

PS. The above is done for illustration. The router is actually a
single T3 interface on a serial port with two subinterfaces to a MPLS
network. I partitioned the DS3 to half bandwidth internal and half
Internet through the vendor's MPLS network.

 
Reply With Quote
 
 
 
 
Ivan Ostreš
Guest
Posts: n/a
 
      01-12-2005
In article <>, bobh1234
@hotmail.com says...
> I have a router that I need to install (and its required I use a
> single router) with both a private link to the rest of my network as
> well as a public Internet link. I'll take one serial to an Ethernet
> port for the private into my LAN, and the other serial with a public
> IP range to a different Ethernet port on the same router. That in
> turn will go to a firewall, then back to my Corporate LAN for Internet
> access.
>
> S0/0 --> F0/0 --> Internal LAN (RFC1918 space mostly)
> S0/1 --> F0/1 --> Public Internet (public routable IP's)
>
> The point of concern is basically within the router. Are there
> examples somewhere that can show how I can secure the router so the
> internal IP range doesn't meet the external IP range? I want to plug
> the hole with the best ACL and policy routing configuration I can
> find. I can't have hackers find their way into my LAN through the
> Internet from this router.
>
>


You could (theoretically) divide router in two virtual routers using
VRF's if software allows it. Then you could add specific interfaces to
specific VRF's. This will give you two separate routing tables and two
virtual routers on one physical box.

Just an idea...

--
-Ivan.

*** Use Rot13 to see my eMail address ***
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
microsoft.public.certification, microsoft.public.cert.exam.mcsa, microsoft.public.cert.exam.mcad, microsoft.public.cert.exam.mcse, microsoft.public.cert.exam.mcsd loyola MCSE 4 11-15-2006 02:40 AM
microsoft.public.certification, microsoft.public.cert.exam.mcsa, microsoft.public.cert.exam.mcad, microsoft.public.cert.exam.mcse, microsoft.public.cert.exam.mcsd loyola Microsoft Certification 3 11-14-2006 05:18 PM
microsoft.public.certification, microsoft.public.cert.exam.mcsa, microsoft.public.cert.exam.mcad, microsoft.public.cert.exam.mcse, microsoft.public.cert.exam.mcsd loyola MCSD 3 11-14-2006 05:18 PM
microsoft.public.certification, microsoft.public.cert.exam.mcsa, microsoft.public.cert.exam.mcad, microsoft.public.cert.exam.mcse, microsoft.public.cert.exam.mcsd realexxams@yahoo.com Microsoft Certification 0 05-10-2006 02:35 PM
microsoft.public.dotnet.faqs,microsoft.public.dotnet.framework,microsoft.public.dotnet.framework.windowsforms,microsoft.public.dotnet.general,microsoft.public.dotnet.languages.vb Charles A. Lackman ASP .Net 1 12-08-2004 07:08 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57