About this list Date view Thread view Subject view Author view Attachment view

From: Herbert Poetzl (herbert_at_13thfloor.at)
Date: Wed 08 Sep 2004 - 09:38:35 BST


On Tue, Sep 07, 2004 at 10:56:36PM +0200, Brian wrote:
> is ist possible ore advisable to install vserver with a DMZ ?
>
> HOST
> eth0 = Internet
> eth0:0 = privat network
>
> Vserver1 for Webserver
>
> eth0 = Internet
> eth0:0 = privat network
>
> Vserver2 for Mail
>
> eth0 = Internet
> eth0:0 = privat network
>
> Vserver3 for mysql
>
> eth0 = privat network

hmm, well, as I see it, all packets will
be sent over the _same_ interface and all
servers will have access to both networks
(maybe even on the same ip ?) so I do not
see much security in that ...

maybe assigning just one private network
address to each vserver, and using S/DNAT
to map specific ports from/to the outside

HTH,
Herbert

> thanx, Brian
> _______________________________________________
> Vserver mailing list
> Vserver_at_list.linux-vserver.org
> http://list.linux-vserver.org/mailman/listinfo/vserver
_______________________________________________
Vserver mailing list
Vserver_at_list.linux-vserver.org
http://list.linux-vserver.org/mailman/listinfo/vserver


About this list Date view Thread view Subject view Author view Attachment view
[Next/Previous Months] [Main vserver Project Homepage] [Howto Subscribe/Unsubscribe] [Paul Sladen's vserver stuff]
Generated on Wed 08 Sep 2004 - 09:39:02 BST by hypermail 2.1.3