Hello again meyergru.
Thanks again for your input on this. I've read all the articles behind the links you suggested and used google translate for the german ones - they really are very informative and I'm surprised your main one isn't pinned in some way or set to appear higher in search results. I suppose I should have just searched for "read this first".
I'm left thinking that what I wanted to do is somewhere between difficult and impossible. I've actually been told before that it was not possible, but that was when I tried to do the same with a Mikrotik RouterOS unit. I was very surprised it could not do it, but I didn't realise it was a general networking thing, rather than a Mikrotik thing.
What would you suggest then, bearing in mind the issue I might have with the realtec NIC too? Specifically regarding your point #4, my Fritz!Box 7530 does allow me to set up static routes. It also has a guest network with different IP range which I could use (though I'm not sure about routing between the two) and has DMZ capability.
From what I can tell my options are:
My ultimate aims were more ambitious than basic packet filtering, but still not too complex. I wanted to:
Will the realtec cause problems for these? (I bought the Zoostom with NIC from an ebay user who had run OPNsense on it for years, apparently).
Any direction would be helpful - just advice. I'll read up on the details myself.
Thanks
Thanks again for your input on this. I've read all the articles behind the links you suggested and used google translate for the german ones - they really are very informative and I'm surprised your main one isn't pinned in some way or set to appear higher in search results. I suppose I should have just searched for "read this first".
I'm left thinking that what I wanted to do is somewhere between difficult and impossible. I've actually been told before that it was not possible, but that was when I tried to do the same with a Mikrotik RouterOS unit. I was very surprised it could not do it, but I didn't realise it was a general networking thing, rather than a Mikrotik thing.
What would you suggest then, bearing in mind the issue I might have with the realtec NIC too? Specifically regarding your point #4, my Fritz!Box 7530 does allow me to set up static routes. It also has a guest network with different IP range which I could use (though I'm not sure about routing between the two) and has DMZ capability.
From what I can tell my options are:
- Configure a distinct 'inner LAN' for my servers and operate the double-NAT router-behind-router option
- Configure a distinct inner LAN for my servers and use Fritz!Box static route to handle it
- Sell the Zoostorm because of the realtec NIC and try to do either of the above with the Mikrotik
- Trust in (and be frustrated by) the capabilities (and lack of capabilities) of the Fritz!Box alone
My ultimate aims were more ambitious than basic packet filtering, but still not too complex. I wanted to:
- inspect/log inbound 'hack' attempts so that I could block specific traffic with aliases (such as geo referenced IPs, entire ranges, specific domains, specific ports) - not possible on Fritz!Box
- set up VLANs (my switch is managed) to ease local traffic congestion - also not possible on Fritz!Box (except maybe using the guest LAN or a DMZ maybe?)
- set up an outbound WireGuard tunnel (to another domain of mine which also uses a Fritz!Box) - Fritz!Box can do inbound WireGuard but not outbound
- block certain types of bandwidth hogs such as advertising
- set up more robust static connectivity for certain devices such as IP TV
Will the realtec cause problems for these? (I bought the Zoostom with NIC from an ebay user who had run OPNsense on it for years, apparently).
Any direction would be helpful - just advice. I'll read up on the details myself.
Thanks