republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Dedicated Linux Server
Search Topic:
Uniqs:
266
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
AdAware Update »
« Microsoft Security Bulletin(s) for 5/9/2006  
AuthorAll Replies


Marshal
Premium
join:2003-11-01
Montreal

Dedicated Linux Server

I'm building a linux box, that will be hosted in a datacenter, here in Montreal.

I have a few concern that i want to ask to get opinions.

That box will be doing webhosting, dns, mail.

I have 4 ipadress. Is it worth to have webhosting listening on 1 ip only, dns on its ip and mail too ?

Will it improve the security side, that people wont know what else is running on this ip ?

Thanks
Frank
--
Vidéotron - Download @ 10 mbits - Upload @ 900 kbits
My home Network


stefaanE
Premium
join:2002-07-10
Luxembourg
·Redwood Virtual

said by Marshal See Profile :

I have 4 ipadress. Is it worth to have webhosting listening on 1 ip only, dns on its ip and mail too ?

Will it improve the security side, that people wont know what else is running on this ip ?
It will not do anything for security to have a separate IP address per service. Scanning four addresses isn't any more difficult than scanning one, and because it's only a single machine, when it's compromised you don't really care through which IP address it happened.

You could get some real security by using User Mode Linux, and configuring a virtual machine for each service. That way, you'd limit the extent of the damage, and restoring the compromised UML machine is a lot easier than re-installing the whole machine.

Reserve one of the IP addresses for the host OS (the real McCoy), and limit access to SSH from your workstation (or configure a VPN). Use the other addresses for one or more UML machines, and you'll have a pretty secure setup.

If you're not committed to Linux, Solaris 10 Zones are easier to set up and give the same type of separation of functions.

Take care,

Stefaan
--
"Technically, Windows is an 'operating system,' which means that it supplies your computer with the basic commands that it needs to suddenly, with no warning whatsoever, stop operating." -Dave Barry


Marshal
Premium
join:2003-11-01
Montreal

I know linux, its just that its the 1st time i build a machine who will be in a datacenter

For Virtual machine, do you have a link or some good references on how do do it ?

Thanks
--
Vidéotron - Download @ 10 mbits - Upload @ 900 kbits
My home Network


John2g
Qui Tacet Consentit
Premium
join:2001-08-10
England
reply to Marshal
You might get more help here: »All Things Unix


stefaanE
Premium
join:2002-07-10
Luxembourg
·Redwood Virtual

reply to Marshal
It's basically a Linux kernel running as a user process. It's pretty nifty, and it works really well. Check out:

»user-mode-linux.sourceforge.net/

and

»usermodelinux.org/

Take care,

Stefaan
--
"Technically, Windows is an 'operating system,' which means that it supplies your computer with the basic commands that it needs to suddenly, with no warning whatsoever, stop operating." -Dave Barry
Forums » Up and Running » Security » SecurityAdAware Update »
« Microsoft Security Bulletin(s) for 5/9/2006  


Friday, 04-Dec 21:57:49 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [145] Avast Antivirus Has Gone Mad
· [126] Comcast Makes NBC Universal Acquisition Official
· [104] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [101] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [83] FCC Ponders Moving From PSTN To IP Voice
· [81] Latest Consumer Reports Survey Not Kind To AT&T
· [74] Sprint Defuses GPS Privacy Media Bomb
· [70] Baltimore To Ban Lazy Cable Installs
· [69] The Bandwidth Hog Does Not Exist
Most people now reading
· False positive in Avast! or is it real? [Security]
· Farewell [Bell Canada]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· [Unlock] TUTORIAL: VONAGE WRTP54G/RTP300 WITH 5.01.04 [VOIP Tech Chat]
· DNS options, what are YOU using? [TekSavvy]
· ZR1 VS The USN Blue Angels! [56k Lookout (Broadband Heavy)]
· Windows 7 boot manager editing questions [Microsoft Help]
· Evading throttling with uTP / uTorrent 1.9a [TekSavvy]
· Google takes aim at browser redirection [Security]