NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

developerNoAdmi's avatar
Jun 09, 2016

Server in DMZ

Hi Everybody,

 

i want to have a server separated from my other network. I think the best is to have this in a DMZ (correct me if i'm wrong). I have a FritzBox 7490 (Modem&WiFi&Router), a GS108E and a FVS318G.

 

I've tried to have

 

My current connection is FritzBox -> GS108E -> FVS318G. This separates into 2: Network 1 (FritzBox, GS108E including WiFi) and Network 2 FVS318G. From 2 i can connect 1 and internet. From 1 i can connect 1 and internet, not network 2. This is not the best solution because the internal WiFi is always reachable. Now my idea was to enable the DMZ port (network 3) and configure some rules, i've add a rule ro allow all outbound connections but here issues starts, i cannot connect to the internet. I thought this should be possible, or?

 

Maybe i've missed something in the whole setup and there is an other config possible.

 

Any help would be appreciated.

Best Mario

 

7 Replies

  • Maybe i can answere myself. I've forget one rule. Now i have a rule allowing everything outbound and a second blocking my home network. Is this enough? I think this is also possible without the dedicated DMZ port, right?

    • DaneA's avatar
      DaneA
      NETGEAR Employee Retired

      Hi developerNoAdmi,

       

      Welcome to the community! :) 

       

      Is it possible that you configure the Fritzbox 7490 as a modem-only device?  Here is what I suggest:  configure the Fritzbox 7490 as a modem-only device then connect it to the WAN port of the FVS318G.  In this way, the FVS318G will be the main firewall router wherein the WAN IP Address will be registered to it.  The FVS318G supports LAN Multi-homing wherein you can add a secondary LAN IP Address.  You will be able to have your server be on a different network by connecting it to the secondary LAN.  Be reminded that if ever the Fritzbox 7490 will be set as modem-only device, its WiFi capability will not be in usable.  You will need an access point to be directly connected to the FVS318G for wireless connection. 

       

      About LAN Multi-homing, read pages 3-10 to 3-11 of the FVS318G reference manual here.

       

       

      Regards,

       

      DaneA

      NETGEAR Community Team

      • Hi DaneA,

         

        yes i think this is the usual way. But is there anything against my current approach, just blocking the home network? Would be nice not to have one more device running 24h a day...

         

        Thank you in advance.

        Mario

NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology! 

Join Us!

ProSupport for Business

Comprehensive support plans for maximum network uptime and business peace of mind.

 

Learn More