WAN / Internet : : DialUp-/PPPoE-/Cable-/whatever-Provider : .-----+-----. | Gateway | (or Router, CableModem, whatever) '-----+-----' | WAN | IP or Protocol | .-----+------. private DMZ .------------. | OPNsense +-----------------+ DMZ-Server | '-----+------' 172.16.16.1 '------------' | LAN | 10.0.0.1/24 | .-----+------. | LAN-Switch | '-----+------' | ...-----+------... (Clients/Servers)
WAN / Internet : : DialUp-/PPPoE-/Cable-/whatever-Provider : .-----+-----. | Gateway | (or Router, CableModem, whatever) '-----+-----' | 10.0.0.1/24 WAN | | .-----:-------. | OPN:sense +-------. | (Br:dge) | | '-----:-------' | | | 10.0.0.253/24 LAN | MGMT | management interface | | .-----+------. | | LAN-Switch +-------' '-----+------' | ...-----+------... (Clients/Servers)
WAN WAN : : : CableProvider : DSL-Provider : : .---+---. .--+--. WAN | Cable | Modems | DSL | WAN2 '---+---' '--+--' | | Ethernet | | PPPoE | | .----+----. .----+----. | Router1 | Router | Router2 | '----+----' '----+----'192.168.101.1/24 | | 192.168.102.1/24 | .----------. | +------| OPNsense |------+ 192.168.101.254/24 '----+-----' 192.168.102.254/24 | LAN | 10.0.0.1/24 | .-----+------. | LAN-Switch | '-----+------' | ...-----+-----... (Clients/Servers)
WAN WAN2 : : : redundant WAN connect : : : .---+---. VRRP .---+---. WAN | Cisco +----------------+ Cisco | WAN2 '---+---' 1.2.3.4/29 '---+---' 1.2.3.5/29 | | 1.2.3.6/29 | | 1.2.3.2/29 | VIP: 1.2.3.1/29 | 1.2.3.3/29 .----+-----. .----+-----. | OPNsense +-------------+ OPNsense | '----+-----' CARP '----+-----' | | 10.0.0.251/24 | 10.0.0.1/24 | 10.0.0.252/24 | .---------. | +------| Switch |-------+ '---------' | ...-----+-----... (Clients/Servers)
| | Upstream | +-----+-----+ | Router | | / Modem | +-----+-----+ .1 | | Transfernetz 192.168.178.0/24 .2 | +-----+-----+ .1 +--------------+ | OPNsense +----------------------+ DMZ - Switch | +-----+-----+ DMZ 192.168.2.0/24 +--------------+ .1 | | | LAN 192.168.1.0/24 +------+------+ |LAN - Switch | +-------------+
+-------------------------+ | | | MODEM | | Router | | | +------------+------------+ | +------------+------------+ | | | OPNSENSE | | Firewall | | | +------+-----------+------+ | | | | +---------------+ | | +----------------+ | | | | | | | ACCESSPOINT +-----------------+ +-----------------+ SWITCH | | WLAN | | LAN | +------+--------+ +-------+--------+ | | | | +-----------+------+-------+-----------+ +-------------+------+------+------------+ | | | | | | | | | | | | | | | |+----+---+ +---+----+ +----+---+ +---+-----+ +---+----+ +----+---+ +----+---+ +----+---+| Tablet | | Phone | | TV | | Console | | MAIL | | Printer| | Cloud | | NAS || | | | | | | | |SERVER | | SERVER | | SERVER | | SERVER|+--------+ +--------+ +--------+ +---------+ +--------+ +--------+ +--------+ +--------+
Sehr gute Idee, die ASCII Netz Diagramme.Schade das es noch kein OpenSource Programm für Netzwerkdiagramme gibt. Was man hier verlinken könnte.Mir ist zumindest keins bekannt.
WAN / Internet . | DialUp-/PPPoE-/Cable-/whatever-Provider | .----'----. | Gateway | (or Router, CableModem, whatever) '----.----' | WAN | IP or Protocol | .----------. private DMZ .------------. | OPNsense ----------------- DMZ-Server | '----.-----' 172.16.16.1 '------------' | | LAN | 10.0.0.1/24 | .------------. | LAN-Switch | '----.-------' | | | -------------------- Clients / Servers