Hi You can set up the SuSE firewall the same way you did for the ISDN connection, but substitute eth1 or whatever for the ISDN interface. ie the external network is the LAN, and the internal network is your friend's LAN.
i.e. 1. I should use IPchains via SuSE firewals to set up masquerading;
Yes, you need 1 IP address on the 'parent' lan which is your external IP for NAT. Masquerade all addresses behind this address.
2. The network card which points to his internal network should be assigned its own address;
Yes, I'm guessing 192.168.x.x would do, just make sure its on a different subnet to the 'parent' LAN.
3. Now the problem : should the second card which points to the network using the leased line have an address on that internal network or the IP address assigned by the ISP for the leased line?
This should have the address on the 'parent' lan.
4. Also, how does one setup an effective firewall that will be sufficient to protect my friend's network?
There's really no difference between routing between ISDN and network and LAN-LAN. Just don't allow anything in unless its needed, paying special attention to DNS/SMTP/etc.
5. What kind of machine (specifications) will be needed to achieve all of the above if all it does is route traffic between the two networks?
Any old machine with 2 NICs, I've acheived this with a 486 before now :-) You probably only need 10Mbps NICs too, unless they've got a crazy leased line :-) Then set the default route for your LAN to be the internal IP of the router, and everything should be great! Hope this helps - John -- To unsubscribe send e-mail to suse-linux-e-unsubscribe@suse.com For additional commands send e-mail to suse-linux-e-help@suse.com Also check the FAQ at http://www.suse.com/support/faq