LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-12-2008, 09:00 PM   #1
knowabitnotalot
LQ Newbie
 
Registered: Oct 2008
Location: Australia
Distribution: OpenSuSe 11
Posts: 5

Rep: Reputation: 0
Question on VPNs and DMZ setup (plus ssh)


Hello everyone, I'm looking at the best way so set up my VPN.

If I have multihomed firewall system with a DMZ (similar to the setup shown at www dot linuxjournal.com/article/4415), what is the best way to set up a VPN connection to my internal network?

The intuitive way would be to forward VPN traffic through the firewall to a VPN server on the internal net. However this seems to go against the whole DMZ philosophy.

The more correct way would be to have a VPN server running in the DMZ, but this would require some form of access to the internal network as well.

Ol;ong a similar line, is it more usual to open ssh access by ssh'ing to the DMZ and allowing a user to ssh from there to the internal network?


Thanks in advance.

Knowabit.
 
Old 10-13-2008, 04:28 AM   #2
rossonieri#1
Member
 
Registered: Jun 2007
Posts: 359

Rep: Reputation: 34
hi,

that is a nice article.
Quote:
what is the best way to set up a VPN connection to my internal network?
it really depends on many things including your routing and firewalling administration skill, and the most important : finance and electricity.

Quote:
The intuitive way would be to forward VPN traffic through the firewall to a VPN server on the internal net. However this seems to go against the whole DMZ philosophy.
no not really. A DMZ not necessarily on a separate subnets than your internal - you can administer a bastion host using your firewalling skills - how a certain traffic from and to bastion host should not communicate with other host in the same subnet?

Quote:
The more correct way would be to have a VPN server running in the DMZ, but this would require some form of access to the internal network as well.
a DMZ best implementation is to have it on a separate subnet than your ordinary LAN - so it must route - from there you can define a better security parameter such as NAT or firewall rules etc.

Quote:
is it more usual to open ssh access by ssh'ing to the DMZ and allowing a user to ssh from there to the internal network?
SSH is only a protocol and operates in its own way - there are many other protocol that any applications need to operate in certain ways.

HTH.
 
Old 10-13-2008, 05:38 AM   #3
knowabitnotalot
LQ Newbie
 
Registered: Oct 2008
Location: Australia
Distribution: OpenSuSe 11
Posts: 5

Original Poster
Rep: Reputation: 0
But assume my DMZ is a different subnet from my internal LAN, the question remains, should my multihomed firewall route VPN traffic via the DMZ or directly to the internal network?
 
Old 10-13-2008, 03:16 PM   #4
knowabitnotalot
LQ Newbie
 
Registered: Oct 2008
Location: Australia
Distribution: OpenSuSe 11
Posts: 5

Original Poster
Rep: Reputation: 0
The other thought I had - does it make more sense to allocate a public IP just for vpn.mydomain.com, put a dedicated firewall there and port it straight through to the internal network? Then I could use the same IP for extenal ssh access.

What do people think?
 
Old 10-14-2008, 05:41 PM   #5
reddazz
LQ Guru
 
Registered: Nov 2003
Location: N. E. England
Distribution: Fedora, CentOS, Debian
Posts: 16,298

Rep: Reputation: 77
Moved: This thread is more suitable in Linux Security and has been moved accordingly to help your thread/question get the exposure it deserves.
 
Old 10-17-2008, 01:48 AM   #6
knowabitnotalot
LQ Newbie
 
Registered: Oct 2008
Location: Australia
Distribution: OpenSuSe 11
Posts: 5

Original Poster
Rep: Reputation: 0
Just giving this a bump.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
question about iptables (DMZ machine connect to other DMZ machine 's publuic IP) wingmak Linux - Security 1 01-20-2007 04:01 PM
LXer: VPNs Illustrated: Tunnels, VPNS, and IPsec -- A Book Review LXer Syndicated Linux News 0 04-17-2006 07:54 PM
ssh setup question moschi Linux - Newbie 3 03-24-2004 08:09 AM
ssh setup question linuxnube Linux - Security 2 01-28-2004 02:37 AM
How to Setup DMZ? Manuel-H Linux - Networking 1 04-06-2003 12:55 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:47 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration