LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 12-22-2005, 05:06 AM   #1
alc@pone
LQ Newbie
 
Registered: Nov 2005
Posts: 7

Rep: Reputation: 0
network topology suggestions


Hi!
I would like to install a linux web/mail server.
I am currently running:
<Internet>
|
|
[ADSL router]
|
|
[Managed switch]
|
|
<internal network>

My questions is where to put it (the server)? I was thinking in a separate segment from the router. Is this a safe configuration? Would could it be improved?
I saw a great document that talked about several topologies and vulnerabilities, i think it mentioned IPCOP and SME Server, and the troubles of running all the services in one macchine. Got it from a link that, i think, was here in the foruns, but now i can't find it. If someone knows this document please post it here.

Any suggestions are welcome.
Thank you.
 
Old 12-22-2005, 05:33 AM   #2
birdseye
Member
 
Registered: Mar 2005
Location: Wales, UK
Distribution: Gentoo, Debian, Ubuntu
Posts: 60

Rep: Reputation: 15
I have put my server behind the router, on the same network as the rest. This way, it is easy to access from the network. Also, you have the advantage of it being behind a firewall. The disadvantage is that, for each port you want to serve, you are going to have to set up port forwarding from the router to your server.

I find this works very well for me.

Rhys
 
Old 12-22-2005, 08:11 AM   #3
ruuster
Member
 
Registered: Dec 2005
Distribution: Slackware 10.2 - bare.i, Slackware 10.1 - scsi.s, Slackware 9.1 - bare.i
Posts: 47

Rep: Reputation: 15
Configure IPTables on your server and if the other systems are Windows, put a personal firewall on each one of them. I use ZoneAlarm Pro on my Windows machines. It does a nice job with a firewall, virus detection, pop-up blocker, etc.

Also, do some hardening. That is, remove all processes, applications, etc. on the server that you do not intend to use.

If you have only 6 or so systems, creating DMZs is not very practical, expecially if a DMZ port is not built into your router or firewall.

Finally, think twice about what sites you go to and what emails you open and respond to. Think three times about what mail attachments you open.
 
Old 12-22-2005, 11:22 AM   #4
alc@pone
LQ Newbie
 
Registered: Nov 2005
Posts: 7

Original Poster
Rep: Reputation: 0
I was consedering adding an IPCOP firewall. Separate the to segments green and orange (DMZ), I just don't know if it would require significant changes in clients or existing infrastructure?
Because the www/mail server is priority then will be moving to some other services (NAS, LDAP; DHCP and probably a SIP Proxy) so i would like to get me a "smart" topology.
Plus i really want to get my hands on that document i talked about .
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
network topology visualization grimse Linux - Software 9 06-19-2005 04:24 PM
determine network topology cutejai Linux - Networking 3 04-15-2005 11:19 AM
graphing a network topology? software? gottin Linux - Software 12 03-17-2005 05:37 PM
Build Network Topology arch4n93l Linux - Networking 1 01-04-2005 07:04 AM
Network Topology chaste Linux - Networking 6 08-06-2002 09:27 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 12:47 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration