View Single Post
  #2   (View Single Post)  
Old 13th October 2008
J65nko J65nko is offline
Administrator
 
Join Date: May 2008
Location: Budel - the Netherlands
Posts: 4,131
Default

If the second modem/router is connected to the Lan switch you are not protected by the OBSD firewall at all.

Insert a third NIC on the OBSD firewall and connect the second modem/router to it.

See http://openbsd.org/faq/pf/pools.html#outgoing for a pf ruleset wich will do load balancing between two internet connections.
If some servers use the first ADSL connection and some the second one, the ruleset could be less complicated.

The most secure and recommended solution is to put all the servers in a so-called DMZ. That would require a fourth NIC though
__________________
You don't need to be a genius to debug a pf.conf firewall ruleset, you just need the guts to run tcpdump
Reply With Quote