To Jail behind NAT or not.

BSD Mail bsdmail at gmail.com
Sun Mar 13 03:15:58 PST 2005


Greetings all,

I have the following topology:

 Internet ----- Gateway ----- DMZ 
                       |
                     LAN

I'm using PF to redirect traffic to the DMZ machine which carries the following:

bind9;postfix;dovecot(imaps,pop3s),openwebmail;apache13;isc dhcp;sfs,ftps
I have ssl certs for services such as mail/web/ftp.

The gateway machine has 3 NICs and doesn't have any service enabled on
its external interface nor internal. Remote access is denied to the
gateway only console access allowed. It only forwards traffic to the
inside DMZ. Also my LAN is on a different subnet
from the DMZ.

If all my services are behind that NAT box is it premature or too much
paranoid to have multiple jails one for postfix another for apache and
so on..on the DMZ machine that is hosting all these services ? Or can
I say that I'm protected to a good extent that jail won't give me any
additional protection because services are behind NAT ?

I use SSH keys to access anymachin on my network, and I have OTP
configured if I needed access from outside my network for college.

Thanks for the insight.

-- 
Regards,


More information about the freebsd-questions mailing list