LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-18-2005, 05:48 PM   #1
Fredstar
Member
 
Registered: Jul 2004
Location: Rochester, NY
Distribution: Fedora9::FreeBSD7.1
Posts: 296

Rep: Reputation: 30
Opinion please


Currently both my servers operate behind my router/firewall. (windows ,game,/linux web) I'm going to be changing my linux over to another ip address to separate it with my gaming server. However, with my current set up i can only pull one ip address through the router and this move will force me to put my linux outside of the router directly connecting to the Internet.

Now im still fairly new despite the tricks i have learned and wanted to know if i can make this server secure. I know that to do this with a windows server is a big security risk. Is iptables enough or should i spend more and get another firewall?

Any helpful hints in securing my server would be appreciated.

Last edited by Fredstar; 03-18-2005 at 06:03 PM.
 
Old 03-18-2005, 10:27 PM   #2
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Obviously the most ideal situation is going to be to put the server behind a dedicated firewall rather that run the border firewall on the host itself. With the firewall running on the server, if the machine is compromised (say by some exploit that allows root access), then you are basically screwed. Once an attacker has root then the game is over (they can modify or bypass the firewall however they like). With a dedicated system you have that added buffer of separation, where they may have the internal host, but the border firewall is still secure. That isn't a major factor, but it still can save you with exploits that utilize some kind of "dial-home" function or drop irc bots on the compromised system.

Long story short (or if you've skipped over the above ), go to ebay and buy a $50 box, throw some RAM in it and setup a dedicated firewall. If you don't have $50 then you run a host firewall and do the best you can to secure it otherwise.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Opinion: What do you think is better? mrchaos Linux - General 9 04-16-2005 11:07 AM
need Yes or No opinion Quickdraw Linux - General 2 10-08-2004 09:19 AM
just your opinion scorpion777 Red Hat 4 06-12-2004 12:09 AM
I want your opinion!!! darthtux General 23 12-07-2003 04:20 PM
In your opinion... DaDdY SnEb Linux - Newbie 8 05-30-2003 11:14 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:13 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration