Re: Port Forwarding HTTP
Jim Stephens <[email protected]>
| Newsgroups | gmane.comp.security.ipcop.user |
|---|---|
| Message-ID | <[email protected]> |
On 10/26/2015 12:05 PM, Matt Wilkerson wrote: > If I have a webserver behind our IPCop firewall and I want to forward an > outside IP to an inside IP, do I just need to forward port 80 or are there > more services that I should forward also. > > > > matt > Matt, this is not a good idea. Web servers are the target of the best exploits out there for external compromising of systems out there. I would strongly recommend you add an additional card to your IPcop and configure an orange network for the server and keep it completely off the green network. Access to the server would be configured via a separate port thru from the outside to the orange network card as well, and remove this server from your green network completely. Then secure that other port which can run sftp (or some secure transfer method) to update your web pages. If your server is compromised and is on your green network there is almost nothing to stop people from compromising everything you have. This sort of expedient way of putting web servers on the internet is how such as the Target and other types of breeches of systems occurred. Some were via phishing and email exploits, but this would make things much easier for both the compromise and taking away information. The secure implementation of the Orange network and barrier is one of the pluses of having a took like IPcop that doesn't exist in other firewalls. thanks Jim ------------------------------------------------------------------------------ _______________________________________________ IPCop-user mailing list [email protected] Manage your subscription or unsubscribe https://lists.sourceforge.net/lists/listinfo/ipcop-user