Greetings all,
I am building a pf firewall intended to protect two networks. The firewall is envisioned to have three interfaces with the following requirements:
1. ExtIf - interfacing with the Internet;
2. IntIf0 - interfacing via a router with a first network. This network is trusted in the sense that all the devices on the network should be allowed to communicate with one another and, when appropriate, with the Internet; and
3. IntIf1 - interfacing via another router with a second network. This network is untrusted in the sense that devices on this network should be allowed to access the Internet, but not any of the devices on the first network, perhaps with the exception of a printer if this will not cause any security issues vis-a-vis other devices on the first network.
It is foreseen that the devices on the second network will be workstations of guests. It would be desirable that the firewall configuration is transparent to the guests, i.e., not requiring any configuration on their workstations.
Is this a firewall based issue, i.e., can I achieve the goals by proper rules at the pf firewall or is it networking issue that needs to be solved by other means than firewall? Can you please point me to a correct solution?
Kindest regards,
M
I am building a pf firewall intended to protect two networks. The firewall is envisioned to have three interfaces with the following requirements:
1. ExtIf - interfacing with the Internet;
2. IntIf0 - interfacing via a router with a first network. This network is trusted in the sense that all the devices on the network should be allowed to communicate with one another and, when appropriate, with the Internet; and
3. IntIf1 - interfacing via another router with a second network. This network is untrusted in the sense that devices on this network should be allowed to access the Internet, but not any of the devices on the first network, perhaps with the exception of a printer if this will not cause any security issues vis-a-vis other devices on the first network.
It is foreseen that the devices on the second network will be workstations of guests. It would be desirable that the firewall configuration is transparent to the guests, i.e., not requiring any configuration on their workstations.
Is this a firewall based issue, i.e., can I achieve the goals by proper rules at the pf firewall or is it networking issue that needs to be solved by other means than firewall? Can you please point me to a correct solution?
Kindest regards,
M