Robert Harlow wrote:
>
> Sirs
>
> Looks like I need to get my old WatchGuard SoHo5 hardware
> firewall back into operation:-( You see it has a great
> mechanism to, very simply, set up and physically block
> *problem domains*...;~/
You should be able to do this with a simple iptables rule as well.
> When my old server-only SME was converted to SME5.6u2
> (server/gateway mode - providing systemic DHCP) I opted to
> use the SME's own firewall for simplicity. The, now unused,
> hardware firewall was put away into storage.
>
> I'm not entirely sure how to effect this insertion... The
> hardware firewall needs to be put between the SME's internet
> side and the broadband's client hardware (my site uses its
> own static IP).
>
> I assume I cannot just reuse the SME's setup settings?
>
> Is it just a simple matter of amending the SME's setup so
> that its internet side uses one of the hardware firewall's
> trusted IPs instead of that of my site's static IP?
Yes, and forwarding ports from the firewall to the SME for the services you need. You may wish to switch back to Server Only mode also.
> Also wondering how I am to control and monitor the hardware
> firewall when it is successfully installed and situated on
> the internet side of the SME's own internal firewall,
> particularly as its webserver access engine requires me to
> use an otherwise internal address of <192.169.111.1>.
It will work fine. I can access our cable modem's web-config at 192.168.100.1 just fine from a LAN PC.
> Having some trouble thinking this through conceptually, so if
> someone has travelled this way before then I'd appreciate
> their feedback;~/
>
> best wishes, Robert