Howell
Storage? I am Storage!
OK, security gurus. I'm redesigning my home network. I will want a firewall, a wireless segment, a dial-up segment, a DMZ and an inside segment. My main concern is about the wireless segment. Except for the switches everything is PC based, most likely Free/OpenBSD.
I’m considering having one box as the firewall and another box just inside the firewall as a Dialup/DMZ router and VPN server. One option is to hang the wireless segment off of the router/VPN server and leave the firewall as simple as possible with only two NICs in it. I would deny all traffic from the wireless segment that was not over the VPN, have static IPs etc. but I’m still concerned about the segment being behind the FW. Maybe the concern is unfounded.
Alternatively, I could have one box that provides all segments. My concern with this is the number of pieces of software and their bug fixes I would have to stay on top of. I plan to keep my software up to date but if a bug is found in the wireless portion I could wait longer to fix it if that software was not facing the outside. Does this sound like a big deal?
I want to treat this as professionally as I can, within my financial means, as I would like to use these concepts later outside the home.
Discuss.
I’m considering having one box as the firewall and another box just inside the firewall as a Dialup/DMZ router and VPN server. One option is to hang the wireless segment off of the router/VPN server and leave the firewall as simple as possible with only two NICs in it. I would deny all traffic from the wireless segment that was not over the VPN, have static IPs etc. but I’m still concerned about the segment being behind the FW. Maybe the concern is unfounded.
Alternatively, I could have one box that provides all segments. My concern with this is the number of pieces of software and their bug fixes I would have to stay on top of. I plan to keep my software up to date but if a bug is found in the wireless portion I could wait longer to fix it if that software was not facing the outside. Does this sound like a big deal?
I want to treat this as professionally as I can, within my financial means, as I would like to use these concepts later outside the home.
Discuss.