Newbie multi-homed routing question
-
I have a cisco ADSL router that has multiple static ip addresses assigned to the dialer (ppp) interface. I then use NAT to expose internal services. I am using cisco ACL's to firewall traffic. The relevant snipped from my configuration:
interface Dialer0
ip address xx.xx.xx.8 255.255.255.248 secondary
ip address xx.xx.xx.9 255.255.255.248 secondary
ip address xx.xx.xx.10 255.255.255.248 secondary
ip address xx.xx.xx.11 255.255.255.248 secondary
ip address xx.xx.xx.12 255.255.255.248 secondary
ip address xx.xx.xx.7 255.255.255.248
…
!
ip nat inside source list 2 interface Dialer0 overload
ip nat inside source static tcp 192.168.0.100 22 xx.xx.xx.10 22 extendableI am concerned that my setup is not very secure and I have bought an ALIX to run pfsense. I would like to know the best setup for this portion of my network. I'm quite a beginner to cisco ios.
As I see it some options are:
- reconfigure my cisco router to give the xx.xx.xx.8-12 static addresses to pfsense and have pfsense multi-homed
- keep my cisco configuration and have pfsense in my internal network. Both cisco and pfsense will provide NAT to expose internal services.
Are these options sensible? Do I have any other options?
Many thanks in advance,
Chris