Author Topic: Question about firewall and subnetting.  (Read 1126 times)

0 Members and 1 Guest are viewing this topic.

Offline firewalkerTopic starter

  • Super Contributor
  • ***
  • Posts: 2450
  • Country: gr
Question about firewall and subnetting.
« on: February 20, 2019, 07:34:47 am »
I have a question found on list of possible question (400 questions) for a test. The question states:

"Design a simple firewall with the help of subnetting ."

Any suggestions?

Alexander.

Become a realist, stay a dreamer.

 

Offline rs20

  • Super Contributor
  • ***
  • Posts: 2318
  • Country: au
Re: Question about firewall and subnetting.
« Reply #1 on: February 20, 2019, 07:39:49 am »
What have you learned about during the course? Linux iptables? Something proprietary?
 

Offline ivaylo

  • Frequent Contributor
  • **
  • Posts: 661
  • Country: us
Re: Question about firewall and subnetting.
« Reply #2 on: February 20, 2019, 07:53:10 am »
You need a device with two network interfaces. Figure out the rest...
 

Offline firewalkerTopic starter

  • Super Contributor
  • ***
  • Posts: 2450
  • Country: gr
Re: Question about firewall and subnetting.
« Reply #3 on: February 20, 2019, 08:55:41 am »
It is not related to a specific courses. It just a test for someone to be able to work as a freelancer network technician. You can answer a question any way you want.

A colleague of me asked me if I know the answer. But the network force is weak in me...

Alexander.
Become a realist, stay a dreamer.

 

Offline onesixright

  • Frequent Contributor
  • **
  • Posts: 624
  • Country: nl
Re: Question about firewall and subnetting.
« Reply #4 on: February 20, 2019, 03:48:02 pm »
You need a device with two network interfaces. Figure out the rest...
Really? Don’t think so.


Sent from my X using Tapatalk
 

Offline rhodges

  • Frequent Contributor
  • **
  • Posts: 306
  • Country: us
  • Available for embedded projects.
    • My public libraries, code samples, and projects for STM8.
Re: Question about firewall and subnetting.
« Reply #5 on: February 20, 2019, 04:23:10 pm »
The most simple firewall that comes to mind is NAT. I would prefer separate interfaces, but if the switch handles 802.1q VLAN tags, the "firewall" could have two virtual interfaces on the one physical.
Currently developing STM8 and STM32. Past includes 6809, Z80, 8086, PIC, MIPS, PNX1302, and some 8748 and 6805. Check out my public code on github. https://github.com/unfrozen
 
The following users thanked this post: firewalker

Offline madires

  • Super Contributor
  • ***
  • Posts: 7763
  • Country: de
  • A qualified hobbyist ;)
Re: Question about firewall and subnetting.
« Reply #6 on: February 20, 2019, 04:28:23 pm »
That task is as stupid as asking someone to design a car with wheels. Seems to be a poor test.
 
The following users thanked this post: firewalker

Offline mansaxel

  • Super Contributor
  • ***
  • Posts: 3554
  • Country: se
  • SA0XLR
    • My very static home page
Re: Question about firewall and subnetting.
« Reply #7 on: February 21, 2019, 07:25:41 pm »
I'd have to chime in on the "badly formulated question" verdict.

A proper exercise/question must have more specific pass/fail requirements.  Something along the lines of:

"Design a firewall setup with these constraints:

 * E-mail traffic shall be permitted from the Internet to and from two specific hosts. Further, all hosts on the network shall be able to send and retrieve e-mail from these hosts.

 * You shall provide for HTTP and HTTPS connectivity to the Internet from an office LAN. Connections to originate from LAN only.

 * A web server shall serve HTTPS queries from all hosts.

 * One part of the office holds engineers. They need to be able to use SSH to hosts on the Internet to work. You can expect their workstations to have static addresses and you will assign them.

 * You have 2001:DB0::/48 as address space. Subnet as needed. The provider has requested you use the first /64 as demarcation LAN between you and their infrastructure. They will have the first IP address on their router, and will route the entire /48 towards the second address on the outside network.

 * Pay special attention to control traffic when constructing rules.

 * Anything not explicitly allowed is forbidden, unless you can demonstrate a valid reason for it. "


This is both specific and non-specific, and it is, IMNSHO, a much better replication of what is needed in real life. There is thinking required, and reading both on the lines and between them. Because the requirements will be un-informed, yet the demands are real.

I spent some years at a large university, teaching network theory and practice to engineering students, and I've seen the commercial crap that is re-runs from the 90s as well.  The world desperately needs clued network engineers, not 14 day bootcamp wonders.

Online ConKbot

  • Super Contributor
  • ***
  • Posts: 1383
Re: Question about firewall and subnetting.
« Reply #8 on: February 21, 2019, 11:33:06 pm »
With such a vague question the appropriate response is
"Give me $1000 per device on the network, and it will be configured, support after 10 business days not included"
 


Share me

Digg  Facebook  SlashDot  Delicious  Technorati  Twitter  Google  Yahoo
Smf