2 x DG834 Dual Firewall Configuration

Associate
Joined
11 Feb 2008
Posts
26
Hi I am a long time lurker finally have a question :)

Basically I run a small web forum off of my DG834GT and I want to make it more secure. By setting it up as a Dual Firewall. Pretty much like this link explains http://en.wikipedia.org/wiki/Demilitarized_zone_(computing)

To make my network a bit more secure. By running it on 2 Subnets so if someone breaks into my Web Server they wont see the rest of my network. As it will be running on a different subnet behind a second DG834.

I think this should be possible with 2 DG834s. I have one DG834GT which is my primary access to the internet and I want to configure a DG834 v2 to run as a second firewall where the rest of my LAN will sit on its own separate subnet.

My knowledge of this sort of thing is pretty limited. But the way I see it is that I need to set up a Static Route to do the job of sending packets through the first firewall into the second to allow net access and mail etc.

The way I have tried so far with out to much luck. Was plug Router 1 into Router 2 via an RJ45 patch cord on the LAN ports. I set up Router 2 with a different subnet and left DCHP turned on both Routers as I do need the 2 separate subnets. But no matter what I do with Static Routes I can not seem to get access to work from router 2 to get to the internet.

Any help at all would be most appreciated.
 
DG is an adsl router i think so it is not possible, you need a cable router or even better look on ebay for an old sonicwall or similar
 
there are loads of old decent easy to configure firewalls which are just too slow for the corporate world.

Sonicwall and Watchguard SOHO products are the ones to go for as they are dead easy to configure yes still over excellent protection. Don't go crazy on a big old nokia box or something as these are not worth the hastle.

(some 3com firewalls are rebranded sonicwalls and can be very cheap)
 
Excellent thanks I will give the 501 a shot.

Will that basically plug RJ45 LAN from my DG834GT to the Pix 501 then I configure the 501 and DG834GT to set up static routes between them and more or less that’s what I need to do ?
 
Excellent thanks I will give the 501 a shot.

Will that basically plug RJ45 LAN from my DG834GT to the Pix 501 then I configure the 501 and DG834GT to set up static routes between them and more or less that’s what I need to do ?

More or less, but seriously, if you haven't configured a PIX before then give yourself plenty of time to do it (and preferably enlist a freind who knows how)
 
OK thanks very much for all the advice. I know Cisco is not the most user friendly hardware in the world. I will give it a whirl :)
 
Back
Top Bottom