Old 09-20-2011, 05:37 PM   #1 (permalink)
Newbie
 
Join Date: Sep 2011
Posts: 6
RudyJCat is on a distinguished road
Default How many firewalls

Hi just started with Untangle and I have a newbie question.

Do I need a firewall in each rack I create if they have no parent rack?

Thanks,

Rudy
RudyJCat is offline  
Old 09-20-2011, 05:48 PM   #2 (permalink)
Master Untangler
 
Join Date: Aug 2011
Location: Buckhannon, WV
Posts: 121
drsminkus is on a distinguished road
Default

You don't need a firewall module in each rack. You only need to add the firewall to the rack if you want firewall protection for traffic assigned to that rack.
drsminkus is offline  
Old 09-20-2011, 05:52 PM   #3 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,454
sky-knight is on a distinguished road
Default

If you don't install a firewall module and the rack in question is a child of a rack that has a firewall module, traffic going through the child rack will be subject to the parent rack's firewall.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 09-20-2011, 05:54 PM   #4 (permalink)
Newbie
 
Join Date: Sep 2011
Posts: 6
RudyJCat is on a distinguished road
Default

Great, thanks for the fast reply...I was just learning about creating racks and was worried that I was leaving some PC's exposed.

Thanks again,

Rudy
RudyJCat is offline  
Old 09-20-2011, 07:32 PM   #5 (permalink)
Master Untangler
 
Join Date: Dec 2010
Location: Echuca, Victoria, Australia
Posts: 256
pazza3564 is on a distinguished road
Send a message via MSN to pazza3564 Send a message via Yahoo to pazza3564 Send a message via Skype™ to pazza3564
Default

Don't forget that with NAT, the internal devices are protected from incoming, except the ports you port forward.
pazza3564 is offline  
Old 09-20-2011, 07:39 PM   #6 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,454
sky-knight is on a distinguished road
Default

Quote:
Originally Posted by pazza3564 View Post
Don't forget that with NAT, the internal devices are protected from incoming, except the ports you port forward.
Something that is going to come to a sudden crashing end when we all move over to IPv6.

I'm looking forward to that reality with an odd mixture of glee and terror.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 09-20-2011, 07:41 PM   #7 (permalink)
Master Untangler
 
Join Date: Dec 2010
Location: Echuca, Victoria, Australia
Posts: 256
pazza3564 is on a distinguished road
Send a message via MSN to pazza3564 Send a message via Yahoo to pazza3564 Send a message via Skype™ to pazza3564
Default

I think some networks will just keep nat, and have their external interface on v6, and internal on v4, and have a translation....
pazza3564 is offline  
Old 09-20-2011, 07:47 PM   #8 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,454
sky-knight is on a distinguished road
Default

One of the major reasons to switch to ipv6 is to get rid of NAT, and all of the problems it causes.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:19 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2