To Jail behind NAT or not.

Loren M. Lang lorenl at alzatex.com
Sun Mar 13 03:24:07 PST 2005


On Sun, Mar 13, 2005 at 03:15:57AM -0800, BSD Mail wrote:
> Greetings all,
> 
> I have the following topology:
> 
>  Internet ----- Gateway ----- DMZ 
>                        |
>                      LAN
> 
> I'm using PF to redirect traffic to the DMZ machine which carries the following:
> 
> bind9;postfix;dovecot(imaps,pop3s),openwebmail;apache13;isc dhcp;sfs,ftps
> I have ssl certs for services such as mail/web/ftp.
> 
> The gateway machine has 3 NICs and doesn't have any service enabled on
> its external interface nor internal. Remote access is denied to the
> gateway only console access allowed. It only forwards traffic to the
> inside DMZ. Also my LAN is on a different subnet
> from the DMZ.
> 
> If all my services are behind that NAT box is it premature or too much
> paranoid to have multiple jails one for postfix another for apache and
> so on..on the DMZ machine that is hosting all these services ? Or can
> I say that I'm protected to a good extent that jail won't give me any
> additional protection because services are behind NAT ?

An NAT router doesn't protect against buffer overflows in apache or
postfix, or any other number of bugs that they may have.  All nat really
does is prevents someone from trying to connect to arbitrary ports of
arbitrary machines behind the router that aren't being forwarded inside,
but it doesn't protect the ports that are forwarded like http to your
dmz machine.

> 
> I use SSH keys to access anymachin on my network, and I have OTP
> configured if I needed access from outside my network for college.
> 
> Thanks for the insight.
> 
> -- 
> Regards,
> _______________________________________________
> freebsd-questions at freebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-questions
> To unsubscribe, send any mail to "freebsd-questions-unsubscribe at freebsd.org"

-- 
I sense much NT in you.
NT leads to Bluescreen.
Bluescreen leads to downtime.
Downtime leads to suffering.
NT is the path to the darkside.
Powerful Unix is.

Public Key: ftp://ftp.tallye.com/pub/lorenl_pubkey.asc
Fingerprint: CEE1 AAE2 F66C 59B5 34CA  C415 6D35 E847 0118 A3D2
 
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
Url : http://lists.freebsd.org/pipermail/freebsd-questions/attachments/20050313/1c2ef4a6/attachment.bin


More information about the freebsd-questions mailing list