LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 05-17-2007, 07:22 AM   #1
a.tsilfidis
LQ Newbie
 
Registered: Feb 2007
Location: Patras, Greece
Distribution: Debian, Slackware
Posts: 14

Rep: Reputation: Disabled
IPCop as one server's firewall


Hi everyone,

I'm running a small mail server and now I would like to connect it to an IPCop firewall. I am pursuaded that it's better to dedicate a single machine to do the firewalling (as I have some old pentium PCs "resting in the courtyard"). The IPCops' manual says that it's not possible for the IPCop to work without the Green network enabled. But in my case I want a very simple setup :

"Internet -> Firewall PC -> Mail Server"

so I would like to use just the RED(internet) and ORANGE(DMZ) network of the IPCop.

Do you know if it's possible?
If not, is there any other Firewall distro who does that?

Thanx in advance!

p.s. I know that I can almost do the same simple firewalling with the IPTables command from my server without any dedicated machine. But reading these forums gave me the impression that it's always best to have a firewall machine without any advanced services running...
 
Old 05-17-2007, 07:26 AM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
someone was asking somethign very similar the other day... there is no orange here. orange is logicall between red and green in terms of security. with no green in it's conventional LAN client format, what would be orange becomes the green.
 
Old 05-17-2007, 08:35 AM   #3
waelaltaqi
Member
 
Registered: Sep 2005
Location: USA, TN
Distribution: CentOS & Ubuntu for Desktop
Posts: 454

Rep: Reputation: 31
if you have a only a mail server then you don't need orange interface. Put the mail server on Green and do port forwarding from red to green to whatever the services on the server.

Code:
  Internet <<<<<<<<RED <<<<<< IPCOP >>>>>>GREEN>>>>>>> Mailserver
Puplic IP <<<<<<<Port Forwarding (SMTP, IMAP, POP3)>>>>>> Private IP
Quote:
orange is logicall between red and green in terms of security
that's not a completly a true statment. A DMZ is surved by a dedicated physical network adapter most of the times. You need a DMZ when you have workstations and servers on Green that shouldn't be expsoded to the outside world as the mailserver you plan to put on orange.
let's say you have a web server and you have another 100 workstation on the network. From a security point of view, it's not recommended to put the workstations on the same network as the webserver. So you put the server on a DMZ to protect other clients from possible security attacks on port 80.
 
Old 05-17-2007, 09:04 AM   #4
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
yeah thanks, i do know what a dmz is... just simplifying it for the actual question.
 
Old 05-18-2007, 03:12 AM   #5
a.tsilfidis
LQ Newbie
 
Registered: Feb 2007
Location: Patras, Greece
Distribution: Debian, Slackware
Posts: 14

Original Poster
Rep: Reputation: Disabled
Thanx guys,

I'm gonna try this out!
 
Old 05-18-2007, 07:30 AM   #6
waelaltaqi
Member
 
Registered: Sep 2005
Location: USA, TN
Distribution: CentOS & Ubuntu for Desktop
Posts: 454

Rep: Reputation: 31
Quote:
Originally Posted by acid_kewpie
yeah thanks, i do know what a dmz is... just simplifying it for the actual question.
sorry ... and i'm sure you do.... just trying to point him to what i believe is the right direction:-)
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
IPCop firewall j447ft Linux - Software 1 05-03-2007 07:21 AM
ipcop firewall apenguinlinux Linux - Security 5 11-28-2005 01:47 AM
ipcop firewall apenguinlinux Debian 1 11-25-2005 04:14 AM
citrix client and ipcop firewall prue3 Linux - Networking 0 02-19-2005 01:35 AM
IPCop + firewall router Robocito Linux - Networking 6 12-04-2004 07:02 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 03:52 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration