LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-22-2006, 08:13 AM   #1
xpucto
Member
 
Registered: Sep 2005
Location: Vienna, Austria
Distribution: Mint 13
Posts: 524

Rep: Reputation: 31
Having a pre-server to log in my main server?


Hi!

The subject of my thread is probably not very clear but I didnīt know how to express it in other words.
I have a webserver.
when I look at the log files, I see that every day (actually every night!) some people try to break in, mainly through ssh. Every day I bann some new ips in the hosts.deny.
10 people have the right to login per ssh. some of them work from home and donī t have a static IP.

In order to avoid all those break in attempts I though about the solution of having a machine which IP would be allowed in my server (it would be then the only allowed IP). The users would have to first loggin into the first machine and from there to loggin in the server.
My idea is that the first machine would only have a sshd and a vnc servers running and therefore would attract much more little attention from people who are scanning around than the main server with its apache, ftps, mailserver, sshd....

Is this strategy useless or does it make sense?
thanks for helping me consolidating my security strategy!
 
Old 11-22-2006, 10:22 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
What you should first do is properly harden the host then pick one method from http://www.linuxquestions.org/questi...d.php?t=340366. *Then* think about other measures. More efficient that way.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Trying to mount a second server to main server with a link fencingfish Linux - Newbie 4 09-11-2006 03:33 PM
Private server with main computer as gateway? Banyon Linux - Networking 5 05-12-2006 11:30 PM
Pre-installed disk in new server sickdude Linux - Software 1 04-18-2006 11:26 PM
Server timeout, force to use main server? AdrianM Linux - Software 0 08-20-2004 08:08 PM
Logins main server... blither Linux - Networking 0 10-06-2003 08:41 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:22 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration