You are not logged in.

#1 2006-09-29 10:36:44

tomk
Forum Fellow
From: Ireland
Registered: 2004-07-21
Posts: 9,839

apache in DMZ + NFS in secure LAN = security nightmare?

If I set up an apache box in my DMZ, with its $HOME on my internal NFS server, am I just asking for trouble?

Offline

#2 2006-09-29 14:30:38

Skyscraper
Member
Registered: 2005-06-20
Posts: 72

Re: apache in DMZ + NFS in secure LAN = security nightmare?

tomk wrote:

If I set up an apache box in my DMZ, with its $HOME on my internal NFS server, am I just asking for trouble?

In my opinion YES! Cause NFS server is in Your LAN network and machines in DMZ (from definition) shouldn't have access to the internal network at all, only realted/established connections from LAN, and maybe SSH.

Maybe You should put NFS server in DMZ ?

Offline

#3 2006-09-29 18:10:47

cactus
Taco Eater
From: t͈̫̹ͨa͖͕͎̱͈ͨ͆ć̥̖̝o̫̫̼s͈̭̱̞͍̃!̰
Registered: 2004-05-25
Posts: 4,622
Website

Re: apache in DMZ + NFS in secure LAN = security nightmare?

tomk, I think the real question is.. why would you need to do that in the first place? perhaps an understanding of your reasoning and needs, would help to understand the balance between usability and security for your situation.


"Be conservative in what you send; be liberal in what you accept." -- Postel's Law
"tacos" -- Cactus' Law
"t̥͍͎̪̪͗a̴̻̩͈͚ͨc̠o̩̙͈ͫͅs͙͎̙͊ ͔͇̫̜t͎̳̀a̜̞̗ͩc̗͍͚o̲̯̿s̖̣̤̙͌ ̖̜̈ț̰̫͓ạ̪͖̳c̲͎͕̰̯̃̈o͉ͅs̪ͪ ̜̻̖̜͕" -- -̖͚̫̙̓-̺̠͇ͤ̃ ̜̪̜ͯZ͔̗̭̞ͪA̝͈̙͖̩L͉̠̺͓G̙̞̦͖O̳̗͍

Offline

#4 2006-09-29 18:32:06

ralvez
Member
From: Canada
Registered: 2005-12-06
Posts: 1,718
Website

Re: apache in DMZ + NFS in secure LAN = security nightmare?

I like to think of the DMZ as what the name implies "an unprotected zone" and therefore anything in there can be compromized. Mind you, security in a network is never 100% "secure".
I would rather (matter of fact I do that) put the machine in the DMZ and set the specific ip of my machine as the only allowed to SSH to the server. Then using ftp mount I mount the directory from the web server into my system and update the web pages with absolute comfort ... just as if it was part of my system. When I'm done I'll unmount and that's it.

Hope this helps.

Rick

Offline

#5 2006-10-02 21:27:01

tomk
Forum Fellow
From: Ireland
Registered: 2004-07-21
Posts: 9,839

Re: apache in DMZ + NFS in secure LAN = security nightmare?

Thanks for the input, all.

Skyscraper - I know it's far from ideal. I'm just trying to gauge  the risk level. And no, I can't put the NFS box in the DMZ - thanks for the suggestion, though.

Cactus - I need to do it because the large hard drive that I thought I'd be using in the web server turned out to be hosed. Currently, I'm not in a position to buy a replacement, so I have a much smaller drive in there, which holds the OS, but very little else. I need more space to hold submissions from users e.g.photos, video, etc, hence this dodgy idea.

ralvez - as above, this is not about building/maintaining the site. I can use your method or various others for that. It's about storage.

Any and all opinions/ideas appreciated. TIA.

Offline

#6 2006-10-02 21:43:45

cactus
Taco Eater
From: t͈̫̹ͨa͖͕͎̱͈ͨ͆ć̥̖̝o̫̫̼s͈̭̱̞͍̃!̰
Registered: 2004-05-25
Posts: 4,622
Website

Re: apache in DMZ + NFS in secure LAN = security nightmare?

Well, aside from swapping the drives out, or buying a new one, it sounds like it is your only real solution.

Just make sure you config the nfs sever to only allow nfs connection from that single host on the dmz, and make sure that your intermediary firewall only allows nfs to that single internal host, from that single host on the dmz.

pray, and make good backups. wink


"Be conservative in what you send; be liberal in what you accept." -- Postel's Law
"tacos" -- Cactus' Law
"t̥͍͎̪̪͗a̴̻̩͈͚ͨc̠o̩̙͈ͫͅs͙͎̙͊ ͔͇̫̜t͎̳̀a̜̞̗ͩc̗͍͚o̲̯̿s̖̣̤̙͌ ̖̜̈ț̰̫͓ạ̪͖̳c̲͎͕̰̯̃̈o͉ͅs̪ͪ ̜̻̖̜͕" -- -̖͚̫̙̓-̺̠͇ͤ̃ ̜̪̜ͯZ͔̗̭̞ͪA̝͈̙͖̩L͉̠̺͓G̙̞̦͖O̳̗͍

Offline

#7 2006-10-02 22:10:29

tomk
Forum Fellow
From: Ireland
Registered: 2004-07-21
Posts: 9,839

Re: apache in DMZ + NFS in secure LAN = security nightmare?

Thanks cactus. Yeah, I'll tie it down to individual IPs/hostnames, and keep a close eye on the logs.

Offline

#8 2006-11-22 13:16:22

tomk
Forum Fellow
From: Ireland
Registered: 2004-07-21
Posts: 9,839

Re: apache in DMZ + NFS in secure LAN = security nightmare?

(Many weeks later)

I've gone for NFS over SSH in the end, in case anyone's interested. Just one pinhole from DMZ  to LAN on port 22, all traffic encrypted, dedicated user on NFS server locked down to one command.

Found the details here (mostly) - when I get the time, I'll add an updated version to the wiki.

Offline

#9 2006-11-22 22:34:34

codemac
Member
From: Cliche Tech Place
Registered: 2005-05-13
Posts: 794
Website

Re: apache in DMZ + NFS in secure LAN = security nightmare?

Well, I'm glad you got it figured out.  I still think it's kind of silly to have a DMZ when you have your $HOME right on there, but clearly it's what your needs are smile

Offline

Board footer

Powered by FluxBB