Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 14 Apr 2009 22:10:12 -0400
From:      Carl Chave <carl@chave.us>
To:        Steve Bertrand <steve@ibctech.ca>
Cc:        Gary Kline <kline@thought.org>, FreeBSD Mailing List <freebsd-questions@freebsd.org>
Subject:   Re: from very early this morning...
Message-ID:  <eaba3b490904141910v2e8cfd1as5cb20328edab39a0@mail.gmail.com>
In-Reply-To: <49E51AD7.4060600@ibctech.ca>
References:  <20090414224141.GA16354@thought.org> <49E51AD7.4060600@ibctech.ca>

next in thread | previous in thread | raw e-mail | index | archive | help
Hi Gary,
Just a couple of thoughts, as your setup sounds similar to mine (and a
lot of others' I'm sure) - I too recently decided to make a concerted
effort to reduce power consumption. =A0I just re-did my file server with
FreeNAS and even though I've got tons of hardware laying around I
decided to buy the Intel 945GCLF mini-itx board based on the Atom
processor, like you find in most netbooks. =A0I put a gigabit NIC in it
though as the onboard is 10/100 (but I knew that and already had the
NIC). =A0It's running great so far.

I'd like to replace my pfSense router/firewall, which is currently
powered by an AMD Duron with another mini-itx board that I've had
forever, it's one of the Via C3 500 Mhz based boards. =A0It's only got
one PCI slot though, which gets me back to the topic at hand.

I just changed my network topology when I stood up the new file
server. =A0It's now:

=A0=A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =
=A0 =A0 =A0 =A0|----------> Wired LAN
ADSL Modem <------> pfSense
=A0=A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =
=A0| =A0 =A0 |----------> WAP ------> WLAN
=A0=A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =
=A0|
=A0=A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =
=A0|----------> DMZ (web server)
Forgive my artwork.

I have my ADSL modem set to bridged ethernet mode which disables all
the router/firewall/dhcp features of the modem and just turns it into
a media/protocol converter between the phone line and the ethernet
cable going to the pfSense box. =A0I use the onboard 10/100 NIC for that
PPPoE connection.

I've got three more NICs installed to make up the remaining
connections. =A0The wired LAN and the WLAN interfaces are bridged. =A0I
initially had these as separate networks but most of my media players
are wireless and the file server is on the wired side so bridging it
was the easiest way (for me!) to get the broadcasts through.

The web server is connected directly to the third NIC at the moment
and is it's own network. =A0It's still behind the firewall but I can
open ports now to it while still protecting the rest of the LAN from
the web server if it get's compromised. =A0At least, that's the theory.

So that's my setup, don't know if that's the kind of feedback you're
looking for but I'd like to hear comments and see what others have
going.

Carl

On Tue, Apr 14, 2009 at 7:23 PM, Steve Bertrand <steve@ibctech.ca> wrote:
>
> Gary Kline wrote:
>
> [...big snip...]
>
> > =A0 =A0 =A0 if i've made any sense so far, great! =A0if not,i'm open fo=
r
> > =A0 =A0 =A0 questions. =A0i'm also open for suggestions on how to alter=
 this
> > =A0 =A0 =A0 network configuration.
> >
> > =A0 =A0 =A0 thanks for reading this far.
> >
> > =A0 =A0 =A0 gary
> >
> >
> > It might be simplest to replace my firewall and my server with
> > low-energy-usage i386 computers; is there a better way?
>
> What are your requirements for your network ie. are you requiring any
> fancy trickery, or is this simply trying to NAT a couple of machines
> behind an ADSL connection?
>
> Steve
> _______________________________________________
> freebsd-questions@freebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-questions
> To unsubscribe, send any mail to "freebsd-questions-unsubscribe@freebsd.o=
rg"



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?eaba3b490904141910v2e8cfd1as5cb20328edab39a0>