V
V
vityaba32016-02-09 08:52:40
linux
vityaba3, 2016-02-09 08:52:40

How to build such a network?

A library in the village... Last time I asked, but didn't say anything concrete, they sent it to the sysadmins...
You need to build it like this

spoiler
174237165b52465fa9bc894ada652a9d.png

A lace with a white ip comes to us.
(computer1) I think to connect it to an old computer and everything should work on it like this
We connect an external line to the zero adapter; the first adapter should issue ip-addresses (but in order not to get into someone else's network), as well as filter the Internet (censor) on some (computer n, n + 1) computers with the possibility of a not very hemorrhoid shutdown, and maybe caching (they say speeds up the loading of frequently opened pages), have a ball.
(server1) Windows server 2003, the Irbis64 server is running on it (it is necessary that an open port be available inside the network)
and (I don’t know how to implement it at all) The server will hold something like a site (cgi and a web server) that must be available from outside and at the white address (but only it (only one port))
(router) Must receive and distribute the Internet (without filtering, but with dhcp (implemented by the router))
(unknown wireless connection) It was installed a long time ago, nothing is known about it, it seems to work, but periodically loses packets. The loss of the snow leopard packet leads to the server (program) freezing. if it is possible to set up some kind of crap that will repeat the sending of the packet if it is lost - I would like to know.
(foreign network) is located at 192.168.1.1
Our Internet is 2 Mbps
Software: All computers on windows (xp--7) computer1 - any OS, probably *bcd & squid, blind, samba (But, anything on -easier)
---------------------------------------------------- -------------------------------------------------- -------------------------------------------------- -----
What doesn't work \ I don't know how
How to make the server visible without problems from the outside at the white address?
How to prevent packet loss on an unknown wireless network? (Is it possible at all?)
What is better to put on computer1 (tried ubuntu server, but didn’t figure out iptables, tried fpsense, but he didn’t see ide-hard, I’ll try again with another hard (sata))
Where is it better to take blacklists for squid'a (standard, school (with estrimism, eroticism, etc) (it was written somewhere that it does not eat large lists (more than 50 mb))

Answer the question

In order to leave comments, you need to log in

7 answer(s)
S
Sergey, 2016-02-09
@edinorog

and? what's the problem then?

A
Artem @Jump, 2016-02-09
curated by the

Take and build.
What is the problem? What do you want? What specifically doesn't work for you? What was the purpose of the question?

A
AntHTML, 2016-02-09
@anthtml

Hmm, with such things, and even the name of the switches as splitters, you will achieve your goal for an extremely long time without a normal admin or at least an integrator.
So far, the questions are only the following:
1. Full configuration of hardware and an approximate list of tasks for server 1
2. Models of all available network equipment (switches, points)
3. Normal (full) network map, not in paint, but in visio, indicating the names of the network equipment and where EVERY (and not n, m) computer is connected
4. why it is necessary to maintain communication with someone else's network if no one goes to each other
5. decoding the type and purpose of the wireless connection, the possibility of replacing it with a wired one
6. Budget for the project
7. Full characteristics of the Internet channel: type of connection, upstream, downstream, the possibility of reservation, the prospects for transition / improvement

R
res2001, 2016-02-09
@res2001

The splitter is apparently all the same a switch/hub/switch.
On computer1, you need to install a firewall with NAT, it is better to use some ready-made assembly, something like pfSense or another similar in functionality. On NAT, forward the port so that the web server is visible on the Internet. At the expense of the "old computer" for the role of computer1 - old age depends on the Internet channel, if there is a normal speed, then thanks to "old age" you may never see it.
Web server - usually use Apache, you can also use Windows IIS.
There is also a "foreign network" on the diagram, it is not clear what kind of entity it is, whether it needs access to the local network / your Internet. According to the mind, between someone else's network and yours, you also need to put a firewall (you can consider using computer1 for this as well) or separate it into a separate VLAN on the switch so that the networks do not intersect.
It’s better to deal with an unknown wireless connection and make it known, otherwise, it’s not even an hour, something will fall off there and you won’t know what to do.
The purpose of the wifi router is not clear, depending on the planned use of wifi, some actions need to be taken. For example, if only your employees will sit on wifi - this is one thing, if it is public with access only inside the network - it is also worth restricting it in access to the network through a firewall or by means of the router itself. If the public one with access to the Internet is a completely different story - you become a telecom operator :) it's better to avoid this.
It would be nice to find a specialist who would set up and support all this, at least "coming".

A
Anton Nagaets, 2016-02-09
@gr1mm3r

Before planning and moving forward, my personal advice is to read LinkMe-Up's " Networks for Little Ones" series of posts . In them you will find many answers to your questions. And in fact, as far as I personally understood, you are making a library based on the requirements of the Federal Law. Half you can do on OpenSource, but filtering, at your level of technical literacy, sorry, you won’t do it. For it, you need to buy a paid solution and you will be calmer.
The easiest thing for you is to take and draw everything that goes where, what, where and to whom should be available, and only after that you will understand how to implement it. 80% of solutions start with drawing and save about 50% of the time at the implementation stage.

A
athacker, 2016-02-09
@athacker

I will support the comrade AntHTML Author
, you should spend time and paint everything exactly - what you have now, what is connected where, what IP addresses it has. Yes, with equipment models and other details. And then describe in no less detail what exactly you want to receive. Otherwise, at the moment, your questions are read in the spirit of "How many tons of clover from each laying hen will be put into incubators after threshing the fallow?"

A
Alexander, 2016-02-09
@Kr1og5n

Why do you need blacklists? This should be done by the provider. We have already said about Yandex.DNS - you can use it.
- In order for the internal resource to be available, it is necessary to forward port 80 on the gateway.
- regarding the wireless channel - look at the pieces of iron, packets cannot be lost just like that, perhaps some kind of interference on the way.
- the computer under the gateway, as I understand it, is ancient. Should I build a local network on it? Buying a simple Mikrotik will be much more reliable, and deploy the necessary resources on the server.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question