LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 04-02-2024, 07:33 AM   #1
ShedDriver
LQ Newbie
 
Registered: Apr 2024
Posts: 2

Rep: Reputation: 0
Firewalling with a web server and users through the same network port


I would like to use a single internet connection for web users and to run a web server. I know how to set up masquerading, and I know how to direct http ports to a webserver, but how can I do both? Somehow I need an unassociated web message (which would normally be rejected by masq) to be sent to the webserver. I other words an external user sees the webserver and internal users browse the web oblivious to that external user.
I get a bad feeling regarding security, but would any solution be any worse than just running a webserver?

Regards

Paul
 
Old 04-02-2024, 12:16 PM   #2
business_kid
LQ Guru
 
Registered: Jan 2006
Location: Ireland
Distribution: Slackware, Slarm64 & Android
Posts: 16,309

Rep: Reputation: 2326Reputation: 2326Reputation: 2326Reputation: 2326Reputation: 2326Reputation: 2326Reputation: 2326Reputation: 2326Reputation: 2326Reputation: 2326Reputation: 2326
Hello, ShedDriver & welcome to LQ.

For most people, the solution is to use the router supplied by Your ISP and that looks after that messing. You don't really say anything we could use to help you
  • How is the internet connected?
  • What distribution are you running?
  • Is your (or any) box on 24/7/365?
  • Have you searched the web and the LQ site for walk-throughs on doing this?
They are just some of the things you don't say. Have a search for a walk-through on your distribution and post the link, and answers to the above. We'll give a 'thumbs up' or 'thumbs down' to it. Then you can post when you hit trouble.

If no pc is always on, you may wast to buy some little cheap SBC to do the web server, and leave that on 24/7. Power usage can be quite small.
 
Old 04-03-2024, 12:41 AM   #3
ShedDriver
LQ Newbie
 
Registered: Apr 2024
Posts: 2

Original Poster
Rep: Reputation: 0
Some clarification.

Erm yes, the linux box is going to be on 24/7, with a webserver I guess people don't expect it to be there only in office hours. Firewalling using nftables, I guess not too many options there. System is Debian-like, but I can't imagine that affects anything.
The router provides port direction, but that is the puzzle. Sending all incoming http packets to the webserver isn't going to do what I want in regards to internal users browsing the web. I any case I would prefer to keep a close watch on my firewall, rather than trusting the router.
 
Old 04-03-2024, 01:42 PM   #4
MikeDeltaBrown
Member
 
Registered: Apr 2013
Location: Arlington, WA
Distribution: Slackware
Posts: 96

Rep: Reputation: 10
What you want is called Port-Forwarding. You can do both Masquerading and Port-Forwarding at the same time. All that is handled in your router.

I don't care how you're connected to the internet and I don't care which distribution you are running.
Your web server should have a static IP address on your internal network. It only needs to be on when you want outside people to access it.

A good book that covers the firewall rules need to implement this is "Designing and Implementing Linux Firewalls and QoS using netfilter, iproute2, NAT and l7-filter" by Packt Publishing. Good explanations and interesting case studies. Well worth the price, IMO.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Shall the firewalling to im with ICQ be worked out port:5190? Xeratul General 2 01-19-2011 02:45 PM
Against firewalling: Is there a website that can do SSH via port 22 ? frenchn00b General 0 11-02-2008 09:08 AM
Firewalling a port at gateway arubin Slackware 2 04-04-2008 02:13 AM
prevent users to run the same script at the same time, on the same machine pvpnguyen Programming 2 09-05-2007 08:52 PM
Tip: Randomizing and firewalling your tcp port range scottman Linux - Security 6 10-02-2004 12:42 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 03:47 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration