ADSL/Stealth + FB address



 
LAN PC ADSL non-NAT installation
Router has single subnet
PCs using real internet addresses
FireBrick allocated a real address also
Internet Router FireBrick LAN PC
LAN PC

In this configuration the FireBrick operates in stealth mode but has a real address. This is normally done to allow external access to the FireBrick configuration.

  1. Pick an address for the FireBrick
  2. Create a LAN subnet with that address and the appropriate subnet, marked stealth
  3. Create a WAN subnet with that address and the appropriate subnet, marked stealth. Ensure this is after the LAN subnet
  4. Set the gateway on the FireBrick to the router on the WAN
  5. PCs can have the router or the FireBrick as their gateway
  6. Always ensure all PCs, and the firebrick subnets have the subnet mask allocated by the ISP.
  7. Adjust filters as required
For external access to FireBrick web management pages :-
  1. Enable a filter allowing WAN to FireBrick for at least TCP port 80
  2. Ensure the admin user has a password, and disable the view and edit rigths for the nobody user
  3. Set the required user to WAN access, and the nobody user to WAN access (to allow the login)
If DHCP allocation to PCs is required :-
  1. Set the DNS server address in the FireBrick so the FireBrick can be used as a DNS relay
  2. Pick a range of addresses for DHCP use, and set these on the FireBrick LAN subnet
  3. Mark the LAN subnet as not stealth - this allows the DHCP server to work correctly
  4. Add a route from LAN to WAN with target IP of the router and proxy ARP. This allows access to the router.
  5. Ensure PCs are set to automatic IP and (for windows) DNS disabled.
This example equally applies to :-
  1. Any installation with a router and a single subnet
  2. BT net start lines
  3. Existing network installations with a router