LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 03-26-2003, 03:50 AM   #1
Grim Reaper
Member
 
Registered: Apr 2002
Distribution: Gentoo 2006.0 AMD64
Posts: 399

Rep: Reputation: 30
My "Hopefully" fairly secure network...


I'm looking at making my network like so:

Code:
The Net
    |
    |
ADSL Modem
    |
    |
  eth0: IP DHCP Assigned by ISP
    |
    |
Firewall (OS: OpenBSD)--eth1: IP 10.0.0.1-------Web Server: IP: 10.0.0.2 (OS: Debian)
    |
    |
   eth2: IP: 192.162.0.1
    |
    |
Switch to workstations
now hopefully this turns out alright and you can understand it...lol.

Now, with these green, orange and red DMZ things you can setup with smoothwall and stuff, how could i do that with this...
I want it to do this: The webserver cannot talk to my internal LAN, it can only talk to my firewall, but the LAN can talk to the web server and view pages, etc...and i put it on a different IP range because it seems more secure, idk why, it just 'seems' to be more secure to me...hehe...

The way i designed it like this is: if my webserver (apache or whatever) gets compromised, it won't be able to view shares, ping, talk or anything to my internal LAN computers, only the firewall so the hacker would then need to try and compromise the firewall (have fun with OpenBSD biatches ) before they can even get near my LAN...

Now, is it all possible? How would i keep that webserver from talking to my lan, etc...

Thanks guys


EDIT: Btw, to move my hardware around to get max performance...

I have about 4 computers on the LAN needing net access and webserver access...I have an AMD K6-2 350 and a 686 PR233 (Is this a pentium 233???)....now, what would need the most CPU, the firewall or webserver? the webserver isn't going to be viewed all the time, only occasionally, whereas the firewall will be used all the time...

RAM isn't an issue, I'll just chuck whatever needs more in them (I'm thinking 128 in the webserver and 64 in the firewall...) as both machines can take SD-Ram...

Last edited by Grim Reaper; 03-26-2003 at 03:54 AM.
 
Old 03-28-2003, 05:38 AM   #2
Paul Johnson
LQ Newbie
 
Registered: Mar 2003
Location: Chelmsford, Essex, UK.
Distribution: Red Hat
Posts: 15

Rep: Reputation: 0
I don't know Smoothwall, so I can't comment on how do do it in that.

> i put it on a different IP range because it seems more secure

It isn't more secure. I'd recommend using 10.* for everything, simply because its the biggest and easiest to remember. However having a specific IP range for the webserver will help because you will need the firewall machine to act as a router. So use 10.1.*.* for the webserver plus any other machines you want to put there in the future, and 10.2.*.* for the rest of the network.

>How would i keep that webserver from talking to my lan, etc...

It looks like you want the firewall to "trust" your web server about as much as it trusts the rest of the Internet (i.e. there is nothing that the webserver should be able to do that J Random Hacker out on the Internet can't). If so then you just need to set up the same rules along each "edge" Internal-Internet, Internal-Webserver, Webserver-Internet. Then add one exception to allow the webserver to accept updates from the internal network.

The web server has to be accessed from your internet address. You will have to set up your firewall to forward incoming TCP packets on port 80 to the firewall.

Paul.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
SSH issue ""Server unexpectedly closed network connection" Errsta_Fonzarelli Linux - Software 12 05-24-2010 02:35 PM
"Xlib: extension "XFree86-DRI" missing on display ":0.0"." zaps Linux - Games 9 05-14-2007 03:07 PM
Microsoft "Secure Authentication" on Linux? KingofBLASH Linux - General 0 02-17-2004 12:10 PM
"ifcfg-ethx" and "network-functions" files peok Linux - Networking 12 08-13-2003 06:06 PM
browsers certificates and "secure" browsing tcaptain Linux - Software 0 07-16-2003 10:25 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 09:06 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration