OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: RE: IP addressing on firewall
From: mouss (usebsdfree.fr)
Date: Mon Aug 21 2000 - 09:52:46 CDT


At 09:42 16/08/00 -0500, Jeffery.Gieserminnesotamutual.com wrote:

>Ronneil,
>
>#Supposed we have the following config:
>#e0 = 172.16.1.1
>#e1 = 172.16.1.5
>#e2 = 222.2.2.2
>#router lan = 222.2.2.1
>
>I like to assign different subnets to all of my network cards. You may
>want to change e1 to 172.16.2.1. Unless my math sucks (which it does) both
>e0 and e1 are in the same subnet.

depends on the netmask! so, e0 = 172.16.1.1/255.255.255.0
and e1=172.16.1.5/255.255.255.255 is ok.

but I agree that it is generally "sane" to reserve logical subnets for each
physical subnet!
otherwise, routing between'em may become a nightmare...

and, if one is using a private addressing scheme, then no rationnal
argument may explain why
the address space is not divided into mny regions, each for a network!
Also, I choose the 10.*. since it is free, I like to have a large one!
(no, Virginia, we are not talking about sex...). Also, typing "ping 10.1"
is handy...

cheers,
mouss

-
[To unsubscribe, send mail to majordomolists.gnac.net with
"unsubscribe firewalls" in the body of the message.]