TreborG2 DD-WRT Novice
Joined: 20 Jun 2010 Posts: 20
|
Posted: Mon Jul 09, 2012 2:52 Post subject: |
|
Public = Outside
Patron = library patrons
Staff = library staff
If you put the printer into the Patron network, they would be more easily able to "see" it, however it also means its more easily abused.
Putting it into the Staff Network, means its easy to see by staff, and you need only open ports from the patron network for the printer.
In the patron router, you would put a static route for the ip address of the printer, pointing to router for staff, which then forwards into the printer.
You want the patron router to know three things.
1) the gateway
2) about the patrons
3) the single route for the single ip address that maps to the Staff Printer
In a best case scenario, you would have two or more public IP addresses, one for patron, one for staff. Thus the patron router does NAT for patrons, the staff router does NAT for staff ... and neither gets natted behind your gateway ... a Double NAT is a bad thing for many reasons..
If you can't get more than 1 ip address.. then you have to have your gateway NAT for all, and still setup two networks, the gateway then has to route, and perform the firewall blocking access from patron to staff, and vice versa, except for the printer ip.
If you've followed a modified version of this:
http://www.dd-wrt.com/wiki/index.php/VLAN_Detached_Networks_%28Separate_Networks_With_Internet%29
then all you're left with needing is routing (permitting) the printer access.
And if you have done the VPN'ing link.. you may already have another option, patrons, printers, staff ... three separate subnets.. though that adds to wiring complexity unless you have a good wiring closet.
Then, just need to update IPTables allowing one ip through. |
|