LinuxQuestions.org
Have you heard the LinuxQuestions.org Podcast?
Go Back   LinuxQuestions.org > Forums > Linux > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
Thread Tools
Old 09-19-2008, 06:22 PM   #1
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Distribution: Suse , Fedora, CentOS, Mandrake, Solaris 8-10, Ubuntu, Debian
Posts: 1,513
Thanked: 0
E-mail/Proxy Server


[Log in to get rid of this advertisement]
I have a client that wants to save some money and would like to combine their e-mail server with squid/proxy server. I view that as a major security issue given that if the proxy server is comprised then then have access to their e-mail server as well. Can someone give me some feedback regarding the security risk in this type of setup.
metallica1973 is offline     Reply With Quote
Old 09-20-2008, 05:45 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 16,668
Blog Entries: 30
Thanked: 274
Maybe fill us in on the network location, access use and proposed security measures of the machine?
unSpawn is offline     Reply With Quote
Old 09-20-2008, 08:29 AM   #3
teruzzi
LQ Newbie
 
Registered: Apr 2005
Location: Ticino - Switzerland
Distribution: More are running on my datacenter depends on HW.
Posts: 12
Thanked: 0
Hello, yes I agree with you.
Normally the proxa server should be a part of the DMZ, the email server is to critical and should be protected by another firewall (for exemple put it in the normal server LAN).

To resume:
- for Proxy, one firewall level is enough;
- for e-mail, two firewall level should be used.

Saluti
MT
teruzzi is offline     Reply With Quote
Old 09-20-2008, 12:10 PM   #4
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Distribution: Suse , Fedora, CentOS, Mandrake, Solaris 8-10, Ubuntu, Debian
Posts: 1,513
Thanked: 0

Original Poster
PHP Code:
T1/ISP Router                         
   
|                     
   |                                 
   |                                         
   |                                         
Cisco 2811 router--------------------------DSL/Router
   
|                                         |
   |                                         |
   |                                    
Dell Switch 
   |                                         |
   |                                         |
3com Switch/Dell Switch                VLAN 10/192.168.5.0
   
|                                         | 
   | 
VLAN 2/192.168.3.0                      |
   |                                         |
MS Mail Server                           MS Server
   
|                                         |
   |                                         |
Web Server                                 Guests 
This is the network setup. you can clearly see that they dont have anything placed in a DMZ and just relying on VLANs. What would be the best way to secure this network with adding a proxy server?
metallica1973 is offline     Reply With Quote
Old 09-21-2008, 03:49 AM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 16,668
Blog Entries: 30
Thanked: 274
You managed to answer one third of what I asked for (-access use, -security measures). VLAN's are Layer 2 "logic" while DMZ means (or should mean AFAIK) physical separation. However, clouding things over, in your OP you also stated that the client has money issues. Finally the question you ask here: ""secure" network utilising proxy?" is fundamentally different from your OP of "risk of combining proxy with MTA". So, all taken into account, if the (vulnerable) Mail Store must not be accessed from the outside then one suggestion could be to use a forwarding MTA in the DMZ. This forwarding MTA could be combined with a proxy since it only forwards e-mail and doesn't store anything. As an aside, maybe separating VLAN's by purpose (servers, users, guests) could make things more efficient (in terms of management) and help avoid mixing devices with disparate security postures.
unSpawn is offline     Reply With Quote
Old 09-21-2008, 12:21 PM   #6
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Distribution: Suse , Fedora, CentOS, Mandrake, Solaris 8-10, Ubuntu, Debian
Posts: 1,513
Thanked: 0

Original Poster
PHP Code:
T1/ISP Router                         
   
|                     
   |                                 
   |                                         
   |                                         
Cisco 2811 router--------------------------DSL/Router
   
|                                         |
   |                                         |
   |                                    
Dell Switch 
   |                                         |
   |                                         |
3com Switch/Dell Switch                VLAN 10/192.168.5.0
   
|                                         | 
   | 
VLAN 2/192.168.3.0                      |
   |                                         |
MS Mail Server                           MS Server
   
|                                         |
   |                                         |
Web Server                                 Guests 
So basically what you are trying to say is it would be better to place a forwarding e-mail server in the DMZ and configure the router/firewall to forward traffic appropriately. Would I place the proxy server in between the T1/ISP router and the Cisco 2811 or behind the 2811?

PHP Code:
T1/ISP Router                         
   
|                     
Proxy Server                                 
   
|                                         
   |                                         
Cisco 2811 router/Firewall----------------DSL/Router
   
|                                         |
   |                                         |
   |<<<<<<<<<<<<<<<<<<<<
DMZ<<<<<<          Dell Switch 
   |                            |            |
   |                            |            |
3com Switch/Dell Switch       Forwarding   VLAN 10/192.168.5.0
   
|                           Email         
   | 
VLAN 2/192.168.3.0        Server        |
   |                             |           |
MS Mail Server>>>>>>>>>>>>>>>>>>>|         MS Server
   
|                                         |
   |                                         |
Web Server                                 Guests 
?
metallica1973 is offline     Reply With Quote

Reply

Bookmarks


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
How to set up a mail and proxy server with the following features? ichauya Linux - Server 3 05-04-2008 11:20 PM
Mail Server on Linux thru Proxy! webboss Linux - Networking 4 01-13-2005 02:35 AM
Proxy & Mail Server nbjayme Linux - Networking 3 06-15-2004 02:42 PM
Proxy and Mail Server nbjayme Fedora 0 06-14-2004 09:17 PM
E-mail problems in a Suse 8.0 Proxy Server (squid) jmafla Linux - Networking 2 03-17-2003 10:13 AM


All times are GMT -5. The time now is 08:51 PM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
RSS2  LQ Podcast
RSS2  LQ Radio
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration