server firewall rules
I am going to have squid proxy on my server and am wondering what firewall rules to set up.
The host has a firewall tracking at the entry to their network. However, I can have an extra one on my server. Is it worth it? Would I only open up port 80 for the proxy? At the moment I have this: Local Port Protocol Action Status 1 All Any 22 TCP Allow Active 2 All Any 80 TCP Allow Active 3 All Any 443 TCP Allow Active 4 All Any 8443 TCP Allow Active 5 All 53 Any UDP Allow Active 6 All 123 Any UDP Allow Active 7 All ICMP Allow Active |
Allow your proxy listening port(in default 3128)
|
Quote:
I can't ping the ssh IP. It has no reverse look up, could that be the issue? I thought for security it was supposed to have no reverse lookup but then how can the ping command find it? |
How is the network set up ?
|
Quote:
|
Quote:
Are they public ip's? |
Quote:
Can't ping the other. |
Where did you get the ip's from?
do you use 192.168.xxx.xxx or 10.0.0.xxx or a public ip? Did you assigned 2 ip's to the networkcard? Why? |
Quote:
The addresses are 213.xxx.xxx.xxx - this I can ping the other is 87.xxx.xxx.xxx both public |
So the server has 1 networkcard with ip 212.xxx.xxx.xxx
You assigned the ip 87.xxx.xxx.xxx to what? are there 2 networkcards? You connect to the server using ssh to ip 212.xxx.xxx.xxx from your home. server => 212.xxx.xxx.xxx => internet => your home computer Where did you setup 87.xxx.xxx.xxx ? |
Quote:
87.xxx.xxx.xxx is setup through their control panel and I can set up different firewall access rules. I can ping and connect to 212 from home using SSH. I cannot ping or connect to 87. but it does not have reverse lookup. |
Quote:
It has nothing to do with reverse lookup Perhaps you can contact the hosting provider. |
Quote:
Now... a guide I read says Quote:
SHould these ports be moved to only be accessible on the 2nd IP address? So, in effect the shared IP only has the proxy server ports open? To change the SSH port, does the SSH listening pot have to be changed in linux? |
All times are GMT -5. The time now is 08:00 PM. |