Re: [opensuse] Web Server in DMZ accessing Database in Internal Network



Hi Theo,

THX for the reply, --> below

Theo van Werkhoven wrote:
LLLActive@xxxxxxx wrote:
Hi all,

At the moment I have an Intranet web server with Apache2 (WS). The web
server provides the web pages for an erp system. The data of the erp
system lies on a DRBD cluster server (CS), with a NFS4 export of the
directory of the database. The web server has the NFS4 mounted as a
directory.

CS (NFS4 export /Data) --> WS (NFS4 mount /Data)

I now want to present the web server to external access via DMZ, but
keep the Data base server (CS) in the Internal Network.

Can a DMZ with 2 SuSEfirewall2 firewalls (FW1 & FW2) be safely
configured for the WS in the DMZ that has the NFS 4 mount for the Data
Base that lies in the Internal Network on the file server, where only
the WS is allowed to cross the Internal FW2 for Data on the CS?

Of course it can, and you do not need two firewalls for that either,
the netfilter package (for which e.g.
SuSEfirewall2 is only a wrapper) can easily filter traffic between
probably a dozen network interfaces.
Come to think: of it: you can not even run two "firewalls"
simultaneously in the Linux kernel,
I meant two separate HW boxes each with SuSEfirewall2
you can run
more that one SuSEfirewall2 wrappers, but that would be silly.
FW1 --> DMZ (Apache WebServer) --> FW2 --> Intranet (DRBD NFS4 /Data)

Is there another way such Data Base data is provided to web servers in
the DMZ than with NFS?

A network socket comes to mind, like e.g. MySQL uses TCP port 3306
between client and server.
Much safer (no RPC running anymore) and easier to filter.

Theo
I know of the socket connection between a SAP-App-Server and
SQL-DB-Server from SAP I installed about 5 years ago. The present Setup
does not separate the machines in that way, but I will look into such a
possibility with this erp.

For the medium term, I need a solution with the NFS4 share being as safe
as possible.

I have read of a 3 NIC SuSEfirewall2 setup, where the one card is
declared EXT, another DMZ, and the third INT. The DMZ NIC is on a switch
to the WS, and the Internal NIC on a switch to the Internal Network
where the CFS with the data lives.

I believe to have read that in such a case, for SuSEfirewall2, linking
between the DMZ and Internal Network is easily opened for DMZ machines
that need access, e.g. the NFS4 Share. Is the NFS4 Share then not open
to the DMZ in general?. How do I protect the NFS4 Share from EXT? Could
it be configured to be only open to the WS (MAC?) on the DMZ-NIC and no
one else in the DMZ or EXT at all, or am I on a wrong track?

How is this set up in YaST of SuSEfirewall2?

TIA - Al
--
To unsubscribe, e-mail: opensuse+unsubscribe@xxxxxxxxxxxx
For additional commands, e-mail: opensuse+help@xxxxxxxxxxxx



Relevant Pages

  • Re: DMZ and file sharing
    ... Never ever use DMZ, a) its an open unlocked door with a big sign saying your ... save/retreive files to/from a restricted area on the LAN. ... and only server. ... You need to consider the safety of the LAN when the web server gets ...
    (microsoft.public.windows.server.sbs)
  • Configuring PIX 515 for OWA in DMZ
    ... Currently I have just a web server and a Linux mail ... I want to move the web server and mail server into the DMZ for more ... access-group 110 in interface outside ...
    (comp.security.firewalls)
  • Configuring PIX 515 for OWA in DMZ
    ... Currently I have just a web server and a Linux mail ... I want to move the web server and mail server into the DMZ for more ... access-group 110 in interface outside ...
    (comp.security.firewalls)
  • Re: [fw-wiz] Securing www server w/Oracle back end.
    ... setup in the DMZ - passing back the requests into the internal web ... server, which - also internally - would pass on requests to the database ... The Linux is setup with the latest and greatest patches ... ... internal users (who would still access the "real" web server). ...
    (Firewall-Wizards)
  • RE: fedora-list Digest, Vol 6, Issue 266
    ... Re: OT: Setting up a forwarding mail domain in DMZ without ... Re: Sound Problem ... downloaded the yum.conf for fedora from Redhat's website. ... Server: Fedora.us Extras ...
    (Fedora)