LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-06-2009, 03:47 PM   #1
packetsmacker
Member
 
Registered: Jun 2006
Posts: 68

Rep: Reputation: 15
iptables and dmz config


I have a Cisco ASA that will have our linux box in the dmz. We have a public IP assigned that is forwarded(not sure if thats the right term am not a Cisco guy) to the private IP so we can access it from the LAN. How do i lock this down. For example i am running an app that uses a web interface to manage it. I need to block the outside world form using that site and allow people on the LAN to use it. Should I use iptable for that if so can i get an example or should we be able to do that on the ASA.
 
Old 10-07-2009, 12:58 PM   #2
lwoos
LQ Newbie
 
Registered: Jan 2008
Distribution: Slackware
Posts: 6

Rep: Reputation: 0
Is the managment webapp run on the same port as the service in the DMZ? If it is I would start by seperating that.
 
Old 10-07-2009, 02:32 PM   #3
nomb
Member
 
Registered: Jan 2006
Distribution: Debian Testing
Posts: 675

Rep: Reputation: 58
Quote:
Originally Posted by packetsmacker View Post
I have a Cisco ASA that will have our linux box in the dmz. We have a public IP assigned that is forwarded(not sure if thats the right term am not a Cisco guy) to the private IP so we can access it from the LAN. How do i lock this down. For example i am running an app that uses a web interface to manage it. I need to block the outside world form using that site and allow people on the LAN to use it. Should I use iptable for that if so can i get an example or should we be able to do that on the ASA.
I think you are trying to say the ASA is routing traffic from your internal LAN to that DMZ?

The box that is in the DMZ has a separate subnet from your regular LAN? Right?

Best practices is to not have a DMZ share the same physical switch that your regular network uses. Not sure your precise setup, but just throwing that out there.

Now if your ASA is routing to the DMZ, then you should also be able to setup an ACL (access control list) on the ASA as well. In which case you can just add rules that say only allow 80, and 443 traffic to the DMZ from your internal LAN subnet.

Again this is just a guess because the details on your setup are kind of lacking.

nomb
 
Old 10-09-2009, 09:42 AM   #4
packetsmacker
Member
 
Registered: Jun 2006
Posts: 68

Original Poster
Rep: Reputation: 15
nomb that is exactly what I am trying to do. I talked it over with the guy that set up the ASA and he said he would add some ACL.

I don't think I can do anything about the switch and the DMZ like you suggested due to work politics. Thanks for the help
 
Old 10-09-2009, 10:17 AM   #5
nomb
Member
 
Registered: Jan 2006
Distribution: Debian Testing
Posts: 675

Rep: Reputation: 58
Quote:
Originally Posted by packetsmacker View Post
nomb that is exactly what I am trying to do. I talked it over with the guy that set up the ASA and he said he would add some ACL.

I don't think I can do anything about the switch and the DMZ like you suggested due to work politics. Thanks for the help
Not a problem glad I could help.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Iptables and DMZ scroogie Linux - Networking 2 02-28-2008 05:39 AM
iptables DMZ garnser Linux - Security 2 12-15-2007 12:14 AM
question about iptables (DMZ machine connect to other DMZ machine 's publuic IP) wingmak Linux - Security 1 01-20-2007 04:01 PM
iptables + DMZ Braytac Linux - Networking 3 10-06-2006 05:57 AM
Smoothwall DMZ config AnotherNewbie Linux - Networking 2 06-09-2002 03:29 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:23 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration