Hi, sorry if this is the wrong place to ask, but I'm planning a new router running m0n0wall and it's my first. I just want to make sure it's possible to set up m0n0 the way I intend to.
For the greater good I would like to share my Internet connection with everyone, But I don't want to share my LAN (obviously).
So my plan was to create this setup using a ALIX.2D3 with 3 Eth interfaces.
The WAN port (eth1) should use my public IP address.
On eth0 and eth2 I want to run DHCP servers using different subnets or however it's best set up
(I'll then use an Wireless AP with DHCP relay for the public LAN and a switch for the private one)
(DSL modem)
|
|
eth1 (public ip)
|
---------(ALIX based m0n0-router)----------------
| |
eth0 (private LAN) eth2 (public LAN)
192.168.0.* 192.168.1.*
Clients on the private lan should have all the usual goodies. Like unlimited bandwith, uPnP etc etc,
The public LAN should have internet access but with capt bandwidth.
mono
Most importantly, I want NO TRAFFIC WHAT SO EVER between the two LANs. I don't want either one of them to even know the other one exists.
Is such a setup possible using m0n0wall?
I don't want to buy the hardware just to find out it's a dead end.
Yes to all questions, I'm doing exactly that right now.
LAN2 is OPT1 basically, m0n0wall also lets you setup DHCP separately for each LAN segment. You use the firewall rules to allow both LAN connection to the Internet, but put in a rule that blocks connections between each other.
You would setup a separate bandwidth shaping ruleset for the public access, that way you can control how much they use. I'm over-simplifying of course, you'll have some trial and error to tweak it the way you like, but it's certainly not a dead end.