Re: Port Forwarding HTTP

Jim Stephens <[email protected]>
Newsgroups gmane.comp.security.ipcop.user
Message-ID <[email protected]>
On 10/26/2015 12:05 PM, Matt Wilkerson wrote:
> If I have a webserver behind our IPCop firewall and I want to forward an
> outside IP to an inside IP, do I just need to forward port 80 or are there
> more services that I should forward also.
>
>   
>
> matt
>
Matt,
this is not a good idea.  Web servers are the target of the best 
exploits out there for external compromising of systems out there. I 
would strongly recommend you add an additional card to your IPcop and 
configure an orange network for the server and keep it completely off 
the green network.

Access to the server would be configured via a separate port thru from 
the outside to the orange network card as well, and remove this server 
from your green network completely.  Then secure that other port which 
can run sftp (or some secure transfer method) to update your web pages.

If your server is compromised and is on your green network there is 
almost nothing to stop people from compromising everything you have.

This sort of expedient way of putting web servers on the internet is how 
such as the Target and other types of breeches of systems occurred.  
Some were via phishing and email exploits, but this would make things 
much easier for both the compromise and taking away information.

The secure implementation of the Orange network and barrier is one of 
the pluses of having a took like IPcop that doesn't exist in other 
firewalls.
thanks
Jim

------------------------------------------------------------------------------
_______________________________________________
IPCop-user mailing list
[email protected]
Manage your subscription or unsubscribe
https://lists.sourceforge.net/lists/listinfo/ipcop-user
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.