Re: [SLE] Iptables rule?

From: Anders Johansson (andjoh_at_rydsbo.net)
Date: 09/07/04

  • Next message: Cleary_Mike_at_emc.com: "RE: [SLE] IBM hard drive"
    To: suse-linux-e@suse.com
    Date: Tue, 7 Sep 2004 16:11:12 +0200
    
    

    On Tuesday 07 September 2004 16:00, Rikard Johnels wrote:
    > How do i (and can i) write rules so specific ftp accounts (authenticated
    > internal users) end up on 192.168.1.2 and my external clients end up on the
    > DMZ server
    >
    > I have personal webpages and home directories plus some NFS folders for the
    > internal network on the internal server that i want to keep there,and i
    > want the clients webpages, along with their respective ftp logins to end up
    > on the DMZ.
    > I know it's probably stupid to mix the webserver like this.
    > But the users work both locally from the internal network using their
    > homefolders, and the homepages from outside with theirftp logon.
    >
    > Any hints and suggestions would be of value.

    My suggestion: let all users go to the DMZ machine when connecting from the
    internet, and then for each directory that you want to have on the internal
    machine, run a mirror job, rsync for example, periodically that pulls it over

    I don't think it's possible to do with iptables alone, but I hope I'll be
    corrected if I'm wrong

    -- 
    Check the headers for your unsubscription address
    For additional commands send e-mail to suse-linux-e-help@suse.com
    Also check the archives at http://lists.suse.com
    Please read the FAQs: suse-linux-e-faq@suse.com
    

  • Next message: Cleary_Mike_at_emc.com: "RE: [SLE] IBM hard drive"

    Relevant Pages

    • Re: Lets talk about firewalls - what do we as a group think a firewall should be/have?
      ... NAT, and the DMZ, since it's already secured, is a good place to tack ... If the "company" is not offering services to the Internet, ... and connections to the internal LAN should ... be by means of a second interface on the server. ...
      (comp.security.firewalls)
    • Re: Where to place the DMZ zone?
      ... hypothetically lets say you have no DMZ hosting an email bridgehead ... If a hacker were to compromise one of your email or web servers (they are ... That is, the Internet accessible servers ... that can be compromised are on your internal network, ...
      (microsoft.public.isa)
    • Re: Prividing Intranet Website Access To External Users
      ... I really wouldnt like to be having my company intranet on the ... I would probably integrate the ldap/dc as a security server on the ... >> The web server will be in the DMZ, and only port 443 will be ... >> intranets to the internet in a secure manner. ...
      (Security-Basics)
    • Re: Forest Trust between Production & DMZ
      ... >> more vulnerable, external, then we are speaking of the trust ... If your DMZ gets whacked, ... To avoid the Swiss-cheese affect on the firewall, ... > Network segregation was a good thing at times when Internet Protocol was ...
      (microsoft.public.windows.server.security)
    • Re: AD in the DMZ - Any thoughts on this scenario?
      ... forest in a DMZ, not one that spans the DMZ and internal network. ... > in our internet facing DMZ. ...
      (microsoft.public.win2000.active_directory)