Welcome to MobyThreads.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in
All support for the MobyThreads Threaded phpBB MOD can now be found on welsolutions at this forum

Running Firewall on Apache Server

 
   Web Hosting and Web Master Forums (Home) -> Apache RSS
Next:  mod_throttle / mod_bandwidth  
Author Message
tim10

External


Since: Jul 01, 2003
Posts: 1



(Msg. 1) Posted: Tue Jul 01, 2003 5:05 pm
Post subject: Running Firewall on Apache Server
Archived from groups: alt>apache>configuration (more info?)

Is running an Apache Server on a 2 x nic system (local and Internet) and
then using Linux firewall to lock down all put port 80 on the internet side
a viable option or am I leaving myself more open than if I ran a seprate
firewall?

Cheers

Tim

 >> Stay informed about: Running Firewall on Apache Server 
Back to top
Login to vote
davide

External


Since: Jul 07, 2003
Posts: 44



(Msg. 2) Posted: Tue Jul 01, 2003 5:05 pm
Post subject: Re: Running Firewall on Apache Server [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Tim Guy <tim DeleteThis @somewhere.com> wrote:
 > a viable option or am I leaving myself more open than if I ran a seprate
 > firewall?

The _best_ would be to have the firewall and the web server on two
separate machine, but if you can't...

Davide<!-- ~MESSAGE_AFTER~ -->

 >> Stay informed about: Running Firewall on Apache Server 
Back to top
Login to vote
spam_this1

External


Since: Jul 02, 2003
Posts: 2



(Msg. 3) Posted: Wed Jul 02, 2003 10:42 am
Post subject: Re: Running Firewall on Apache Server [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Tim Guy" wrote...
 > Is running an Apache Server on a 2 x nic system (local and Internet) and
 > then using Linux firewall to lock down all put port 80 on the internet
side
 > a viable option or am I leaving myself more open than if I ran a seprate
 > firewall?

Tim,

The "best practise" would be to run them on separate boxes. This is largely
due to the fact that if you run multiple apps (servers) on the same box as
the firewall, and there is an exploitable flaw in one of those apps, your
entire network can be compromised. Keeping a minimum number of points of
ingress is the "best" way to go.

Having said all that, it doesn't mean that you can't do it. In fact I know
a popular "geek site" that doesn't run a DMZ for their servers - they all
sit out on the internet with packet filtering on each box. So each server
(web, database, mail, irc, proxy - the lot) are a firewall for themself too.
Never been cracked/hacked despite many attempts over many years.

I run many servers on the inside interface of my firewall, plus
ssh/mail/web/nntp/jabber on the external interface. There have never been
any problems with my config (although on a P100 with 64Mb it does have a
tendency to bog down occasionally). My only advice is to READ as much as
you can about network security and common exploits for the apps (servers)
you intend to run on your firewall, then carefully poke holes in your
firewall to allow everything to talk as it should. Check out Security Focus
(http://www.securityfocus.com/) as good starting point Smile

Good luck,

James
_______________________________________
A random quote of nothing:
He played the king as if afraid someone else would play the ace.
-- John Mason Brown, drama critic<!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: Running Firewall on Apache Server 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Known issues with running Apache and IIS simultaneously? - Hello, My company is considering running Apache and IIS together on one server. I have researched the possibilities of doing this on the web, but I have found little information apart from basic configuration instructions and some known configuration..

Odd apache header (~~~~~~~~~~~~~~:) - Anyone know what this header is? My copy of apache returns it, and I've seen others do it too. Richard.

Apache doesn't start - When I try to start Apache, I got the following error: <32548> only one usage of each socket address <> is normally permitted. make_sock: could not bind to address 0.0.0.0:80. I've looked for answers all over the FAQ, bug report, manuals and...

Using Java to modify Apache...? - Has anyone found any Java-based utilities or code to modify the Apache configuration? I need to write something that will modify (parts of) the apache configuration (httpd.conf) and then re-start the server so that the changes are recognized. Thanks.

Apache+Tomcat+Cocoon - Anyone ever get those 3 latest-stable release ever work? I got Apache+Tomcat works fine. But I can't get Cocoon to work. All I got when I did http://localhost:8080/cocoon is a directory listing. Helps are greatly appreciated. PS: Its too confusing to....
   Web Hosting and Web Master Forums (Home) -> Apache All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]