Welcome to Linux Forums! With a comprehensive Linux Forum, information on various types of Linux software and many Linux Reviews articles, we have all the knowledge you need a click away, or accessible via our knowledgeable members.
Write an article for LinuxForums Today! Win Great Prizes!
Find the answer to your Linux question:
New to Linux Forums? Register here for free!
    Linux Forums > GNU Linux Zone > Linux Security > Trying to decrease the amount of PCs on home LAN

Forgot Password?
 Linux Security   Discussion about keeping your machines secure, and the crackers out.

Site Navigation
Linux Articles
Linux Forums
Linux Downloads
Linux Hosting
Free Magazines
Job Board
IRC Chat
RSS Feeds
Linux Forum Topics
Linux Forums
Your Distro
Linux Resources
GNU Linux Zone
The Community
Reply
 
Thread Tools Display Modes
Old 08-19-2008   #1 (permalink)
Just Joined!
 
Join Date: Dec 2007
Posts: 3
Trying to decrease the amount of PCs on home LAN

Hi all,

I'm trying to decrease the amount of PCs I have at home while keeping my network and data secure. I have around 4 servers on my network, plus user PCs and laptops.

My network is fairly secure right now. I have my web-ftp server in a dmz with no access to my LAN, a strong firewall and mostly all ports blocked for my LAN. It looks something like this:

Quote:
firewall - (server A)

ssh - (server B)
squid - (server B)
virtual_machine (secure browsing) - (server B)
jinzora (music server) - (server B)

ftp - (Server C DMZ)
www - (Server C DMZ)

file_share - (server D)
I was thinking of getting a new box with up to date hardware (the ones I have are all p3s and bellow), and run everything of it. What you guys think? Lots of security risks there?

Any input is greatly appreciated.

Thanks,

Vic.
victorbrca is offline  



Reply With Quote
Old 08-21-2008   #2 (permalink)
Linux Engineer
 
Lazydog's Avatar
 
Join Date: Jun 2004
Location: The Key Stone State
Posts: 1,360
I would say keep your DMZ stuff on their own box and separated from your LAN. Block all new connections from the DMZ as this box shouldn't be making any new connections. This would only bring you down to 3 boxes and the p3 should be strong enough to use as a firewall so you really only would need 2 boxes if buying new.
__________________

Regards
Robert

Linux
The adventure of a life time.

Linux User #296285
Get Counted
Lazydog is offline   Reply With Quote
Old 08-21-2008   #3 (permalink)
Linux Engineer
 
Join Date: Nov 2007
Posts: 1,284
I can see a few ways to make this work. I'd strip down to how many *physical* machines are *needed* and then run them virtualized. It looks like 3 machines are needed:

> Firewall
> DMZ Server/Apps
> Internal Server/Apps

So on one physical box with 2 NIC's:

Install host OS and virtualization software - create 3 VM's.

One NIC is used by the VM's and face "externally" while the other NIC is connected to the internal network (if there are other machines internally.)
HROAdmin26 is offline   Reply With Quote
Old 08-21-2008   #4 (permalink)
Just Joined!
 
Join Date: Dec 2007
Posts: 3
What I'm thinking on doing is converting everything to vm. I might get a headless box, with quadcore and 4GB of memory. That should do the trick.

My smoothwall firewall (ServerA) would be substituted for my dd-wrt firewall. The host OS would act as a file-server and vm-server (ServerD). I'd have one vm for web-ftp with an individual NIC (ServerC); another vm for secure browsing and the last vm for jinzora-quid-ssh (ServerB).

What do you guys think?
victorbrca is offline   Reply With Quote
Old 08-22-2008   #5 (permalink)
Linux Engineer
 
Lazydog's Avatar
 
Join Date: Jun 2004
Location: The Key Stone State
Posts: 1,360
If you are looking for security then the firewall box should be a stand alone box running nothing but the firewall. I would agree with HROAdmin26's idea of how to do it.
__________________

Regards
Robert

Linux
The adventure of a life time.

Linux User #296285
Get Counted
Lazydog is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Free Magazines
A Newbie's Getting Started Guide to Linux
Learn the basics of the Linux operating systems. Get to know what it is all about, and familiarize yourself with the practical side. Basically, if you're a complete Linux newbie and looking for a quick and easy guide to get you started this is it.
subscribe
Run Your Own Web Server Using Linux & Apache - Free 191 Page Preview
Learn about everything you'll need to build and maintain your Linux servers, and to deploy Web applications to them.
subscribe
Open Source Security Myths Dispelled
Dispel the five major myths surrounding Open Source Security and gain the tools necessary to make a truly informed decision for your IT organization
subscribe
InformationWeek
InformationWeek is the only newsweekly you'll need to stay on top of the latest developments in information technology.
subscribe



All times are GMT. The time now is 08:01 AM.






© 2000 - - All Rights Reserved - Property of  MAS Media

Content Relevant URLs by vBSEO 3.3.1