View previous topic :: View next topic |
Author |
Message |
Bellrang QT Tux's lil' helper
Joined: 16 May 2003 Posts: 81
|
Posted: Wed Jan 28, 2004 2:14 am Post subject: Dual External NIC Firewall/Router |
|
|
Here's my situation:
My university currently has a packet shaping / priority queue system in place to help equally share our bandwidth during peak hours. At times, this can be quite painful. Since the shaping is done per IP address, I'm thinking that I could possibly increase my browsing speeds if I could direct web requests through two IPs simultaneously.
So here's my thinking:
Could I set up a router that had two "external" NICs (plugged into my school's ethernet). Then a single NIC on the inside of the router would be plugged into my private LAN and would share the requests for outside pages over the two NICs (thus *almost* doubling my priority in the packet shaping queue).
Possible? Impossible? Ideas? This doesn't have to be a Gentoo solution (a floppy distro router/firewall would actually be really cool - I have hard drives just spinning aimlessly). Would the Mandrake Multi-network firewall package be able to accomplish something like this? I'm open to lots of ideas.
To throw one curveball - my webserver is inside the private LAN. I would need to be able to forward ports through at least one of the ports (although being able to forward port 80 on one external IP to a certain box internally and 80 on the other nic to a different box - all on the same router - would be awesome!) _________________ I <3 forums.gentoo.org |
|
Back to top |
|
|
ckdake l33t
Joined: 10 Apr 2003 Posts: 889 Location: Atlanta, GA
|
Posted: Wed Jan 28, 2004 2:37 am Post subject: |
|
|
It sounds very possible to me. I have never heard of someone doing it, so I don't know if one of the firewall based distributions would be set up to do that easily or if you are better off just doing the rules yourself. I don't know about how it would balance http get requests, but you shoudl be able to balance the actual traffic. Will your school really give you two IP addresses though? _________________ http://ckdake.com/ |
|
Back to top |
|
|
Bellrang QT Tux's lil' helper
Joined: 16 May 2003 Posts: 81
|
Posted: Wed Jan 28, 2004 3:32 am Post subject: |
|
|
ckdake wrote: | It sounds very possible to me. I have never heard of someone doing it, so I don't know if one of the firewall based distributions would be set up to do that easily or if you are better off just doing the rules yourself. I don't know about how it would balance http get requests, but you shoudl be able to balance the actual traffic. Will your school really give you two IP addresses though? |
Yeah... our systems all get "registered" to our ID here... we can have something like 6 or 7 IPs... I know it seems crazy. _________________ I <3 forums.gentoo.org |
|
Back to top |
|
|
ckdake l33t
Joined: 10 Apr 2003 Posts: 889 Location: Atlanta, GA
|
Posted: Wed Jan 28, 2004 3:53 am Post subject: |
|
|
That is incredibly amazing. I go to GT and when I lived on campus each dorm was a C block and we each got one IP and supposedly weren't allowed to use routers but I won't get into that. Multiple IP addresses would have been soooo nice. Are your IP addresses public?
also Quote: | To throw one curveball - my webserver is inside the private LAN. I would need to be able to forward ports through at least one of the ports (although being able to forward port 80 on one external IP to a certain box internally and 80 on the other nic to a different box - all on the same router - would be awesome!) |
That should be absoltuley no problem at all to forward ports that way. You would have "one router" so to say, but all that really matters is the interfaces so you could forward and move around traffic between any of them any way you wanted to. _________________ http://ckdake.com/ |
|
Back to top |
|
|
Bellrang QT Tux's lil' helper
Joined: 16 May 2003 Posts: 81
|
Posted: Wed Jan 28, 2004 5:06 am Post subject: |
|
|
Yeah, the IPs are public too
Congrats on post 500.
I guess I'll have look into things this weekend a little more. _________________ I <3 forums.gentoo.org |
|
Back to top |
|
|
tripmcneely187 n00b
Joined: 10 Dec 2003 Posts: 5 Location: Iowa
|
Posted: Wed Jan 28, 2004 5:39 am Post subject: |
|
|
Are you at Iowa State by any chance? That bandwidth sharing thing sounds familiar |
|
Back to top |
|
|
Bellrang QT Tux's lil' helper
Joined: 16 May 2003 Posts: 81
|
Posted: Wed Jan 28, 2004 7:16 pm Post subject: |
|
|
tripmcneely187 wrote: | Are you at Iowa State by any chance? That bandwidth sharing thing sounds familiar |
Indeed _________________ I <3 forums.gentoo.org |
|
Back to top |
|
|
TheCoop Veteran
Joined: 15 Jun 2002 Posts: 1814 Location: Where you least expect it
|
Posted: Wed Jan 28, 2004 7:54 pm Post subject: |
|
|
have a look at shorewall, it is a very powerful iptables wrapper that can do anything iptables can _________________ 95% of all computer errors occur between chair and keyboard (TM)
"One World, One web, One program" - Microsoft Promo ad.
"Ein Volk, Ein Reich, Ein Führer" - Adolf Hitler
Change the world - move a rock |
|
Back to top |
|
|
|