LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-19-2008, 05:22 PM   #1
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Posts: 2,190

Rep: Reputation: 60
E-mail/Proxy Server


I have a client that wants to save some money and would like to combine their e-mail server with squid/proxy server. I view that as a major security issue given that if the proxy server is comprised then then have access to their e-mail server as well. Can someone give me some feedback regarding the security risk in this type of setup.
 
Old 09-20-2008, 04:45 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Maybe fill us in on the network location, access use and proposed security measures of the machine?
 
Old 09-20-2008, 07:29 AM   #3
teruzzi
LQ Newbie
 
Registered: Apr 2005
Location: Ticino - Switzerland
Distribution: Differents were running on my datacenter depends on HW
Posts: 12

Rep: Reputation: Disabled
Hello, yes I agree with you.
Normally the proxa server should be a part of the DMZ, the email server is to critical and should be protected by another firewall (for exemple put it in the normal server LAN).

To resume:
- for Proxy, one firewall level is enough;
- for e-mail, two firewall level should be used.

Saluti
MT
 
Old 09-20-2008, 11:10 AM   #4
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Posts: 2,190

Original Poster
Rep: Reputation: 60
PHP Code:
T1/ISP Router                         
   
|                     
   |                                 
   |                                         
   |                                         
Cisco 2811 router--------------------------DSL/Router
   
|                                         |
   |                                         |
   |                                    
Dell Switch 
   |                                         |
   |                                         |
3com Switch/Dell Switch                VLAN 10/192.168.5.0
   
|                                         | 
   | 
VLAN 2/192.168.3.0                      |
   |                                         |
MS Mail Server                           MS Server
   
|                                         |
   |                                         |
Web Server                                 Guests 
This is the network setup. you can clearly see that they dont have anything placed in a DMZ and just relying on VLANs. What would be the best way to secure this network with adding a proxy server?
 
Old 09-21-2008, 02:49 AM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
You managed to answer one third of what I asked for (-access use, -security measures). VLAN's are Layer 2 "logic" while DMZ means (or should mean AFAIK) physical separation. However, clouding things over, in your OP you also stated that the client has money issues. Finally the question you ask here: ""secure" network utilising proxy?" is fundamentally different from your OP of "risk of combining proxy with MTA". So, all taken into account, if the (vulnerable) Mail Store must not be accessed from the outside then one suggestion could be to use a forwarding MTA in the DMZ. This forwarding MTA could be combined with a proxy since it only forwards e-mail and doesn't store anything. As an aside, maybe separating VLAN's by purpose (servers, users, guests) could make things more efficient (in terms of management) and help avoid mixing devices with disparate security postures.
 
Old 09-21-2008, 11:21 AM   #6
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Posts: 2,190

Original Poster
Rep: Reputation: 60
PHP Code:
T1/ISP Router                         
   
|                     
   |                                 
   |                                         
   |                                         
Cisco 2811 router--------------------------DSL/Router
   
|                                         |
   |                                         |
   |                                    
Dell Switch 
   |                                         |
   |                                         |
3com Switch/Dell Switch                VLAN 10/192.168.5.0
   
|                                         | 
   | 
VLAN 2/192.168.3.0                      |
   |                                         |
MS Mail Server                           MS Server
   
|                                         |
   |                                         |
Web Server                                 Guests 
So basically what you are trying to say is it would be better to place a forwarding e-mail server in the DMZ and configure the router/firewall to forward traffic appropriately. Would I place the proxy server in between the T1/ISP router and the Cisco 2811 or behind the 2811?

PHP Code:
T1/ISP Router                         
   
|                     
Proxy Server                                 
   
|                                         
   |                                         
Cisco 2811 router/Firewall----------------DSL/Router
   
|                                         |
   |                                         |
   |<<<<<<<<<<<<<<<<<<<<
DMZ<<<<<<          Dell Switch 
   |                            |            |
   |                            |            |
3com Switch/Dell Switch       Forwarding   VLAN 10/192.168.5.0
   
|                           Email         
   | 
VLAN 2/192.168.3.0        Server        |
   |                             |           |
MS Mail Server>>>>>>>>>>>>>>>>>>>|         MS Server
   
|                                         |
   |                                         |
Web Server                                 Guests 
?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to set up a mail and proxy server with the following features? ichauya Linux - Server 3 05-04-2008 10:20 PM
Mail Server on Linux thru Proxy! webboss Linux - Networking 4 01-13-2005 01:35 AM
Proxy & Mail Server nbjayme Linux - Networking 3 06-15-2004 01:42 PM
Proxy and Mail Server nbjayme Fedora 0 06-14-2004 08:17 PM
E-mail problems in a Suse 8.0 Proxy Server (squid) jmafla Linux - Networking 2 03-17-2003 09:13 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:58 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration