Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.os.linux.networking > #1169 > unrolled thread
| Started by | buck <buck@private.mil> |
|---|---|
| First post | 2012-03-15 15:45 +0000 |
| Last post | 2012-03-16 18:41 +0000 |
| Articles | 15 — 5 participants |
Back to article view | Back to comp.os.linux.networking
multi domains, single IP buck <buck@private.mil> - 2012-03-15 15:45 +0000
Re: multi domains, single IP Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-03-15 20:32 +0100
Re: multi domains, single IP buck <buck@private.mil> - 2012-03-15 20:54 +0000
Re: multi domains, single IP Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-03-15 23:05 +0100
Re: multi domains, single IP buck <buck@private.mil> - 2012-03-16 18:29 +0000
Re: multi domains, single IP Chris Davies <chris-usenet@roaima.co.uk> - 2012-03-16 21:09 +0000
Re: multi domains, single IP unruh <unruh@invalid.ca> - 2012-03-16 23:42 +0000
Re: multi domains, single IP Chris Davies <chris-usenet@roaima.co.uk> - 2012-03-17 09:30 +0000
Re: multi domains, single IP buck <buck@private.mil> - 2012-03-17 17:47 +0000
Re: multi domains, single IP Chris Davies <chris-usenet@roaima.co.uk> - 2012-03-18 09:14 +0000
Re: multi domains, single IP Chris Davies <chris-usenet@roaima.co.uk> - 2012-03-15 22:16 +0000
Re: multi domains, single IP Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-03-16 00:35 +0100
Re: multi domains, single IP Chris Davies <chris-usenet@roaima.co.uk> - 2012-03-16 09:03 +0000
Re: multi domains, single IP Tauno Voipio <tauno.voipio@notused.fi.invalid> - 2012-03-16 09:11 +0200
Re: multi domains, single IP buck <buck@private.mil> - 2012-03-16 18:41 +0000
| From | buck <buck@private.mil> |
|---|---|
| Date | 2012-03-15 15:45 +0000 |
| Subject | multi domains, single IP |
| Message-ID | <jjt2q702p29@news6.newsguy.com> |
I know it is possible to do this on a single computer. What I need to know is if it is possible to have each domain be specific to its own computer, and how to accomplish that. There is only one WAN IP address available. The setup is that one (Slackware) box's eth1 is connected to the ISP (WAN) while its eth0 is connected to a switch (LAN, with 192.168 IPs). Obviously, only one WAN connection is possible. At this time, there are 3 domains using that IP. I tried to use iptables' "string" match in the nat table to redirect incoming packets to the LAN IP of the computer indicated by the domain name. "-m string --string DOMAIN.NAME -j DNAT" in PREROUTING doesn't work; the domain string is not matched. The only required services for each of these domains are ftp and http. More specifically, domain A needs to provide ftp and http, domain B needs ftp, http, rsync & ssh; domain C needs those and more. Am I doomed to having these services all be on the Slackware box? -- buck
[toc] | [next] | [standalone]
| From | Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> |
|---|---|
| Date | 2012-03-15 20:32 +0100 |
| Message-ID | <jjtg50$lmp$1@saria.nerim.net> |
| In reply to | #1169 |
Hello, buck a écrit : > I know it is possible to do this on a single computer. What I need to > know is if it is possible to have each domain be specific to its own > computer, and how to accomplish that. > > There is only one WAN IP address available. > > The setup is that one (Slackware) box's eth1 is connected to the ISP > (WAN) while its eth0 is connected to a switch (LAN, with 192.168 IPs). > Obviously, only one WAN connection is possible. What do you mean ? > At this time, there are 3 domains using that IP. Do you mean 3 domain names with DNS address ressource records pointing to that address ? > I tried to use iptables' "string" match in the nat table to redirect > incoming packets to the LAN IP of the computer indicated by the domain > name. "-m string --string DOMAIN.NAME -j DNAT" in PREROUTING doesn't > work; the domain string is not matched. That cannot work. The nat chains, where you can use the DNAT target, see only the first packet (SYN) of a connection, which does not contain any data. The target host name is contained is a subsequent packet, but then it is too late, the NAT mapping cannot be changed. > The only required services for each of these domains are ftp and http. > More specifically, domain A needs to provide ftp and http, domain B > needs ftp, http, rsync & ssh; domain C needs those and more. For HTTP 1.1, you need a reverse proxy. For other protocols such as FTP, the only "solution" is to use a different address or port with each domain name : unlike HTTP, these protocols do not advertise the targed host name in the payload. > Am I doomed to having these services all be on the Slackware box? The problem would be the same on a single box.
[toc] | [prev] | [next] | [standalone]
| From | buck <buck@private.mil> |
|---|---|
| Date | 2012-03-15 20:54 +0000 |
| Message-ID | <jjtktr02rrv@news4.newsguy.com> |
| In reply to | #1172 |
Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> wrote in news:jjtg50 $lmp$1@saria.nerim.net: > Hello, > > buck a écrit : >> I know it is possible to do this on a single computer. What I need to >> know is if it is possible to have each domain be specific to its own >> computer, and how to accomplish that. >> >> There is only one WAN IP address available. >> >> The setup is that one (Slackware) box's eth1 is connected to the ISP >> (WAN) while its eth0 is connected to a switch (LAN, with 192.168 IPs). >> Obviously, only one WAN connection is possible. > > What do you mean ? It is not possible to connect more than one computer to the WAN. Conflicts occur otherwise; the OS complains that more than one computer has the same IP. >> At this time, there are 3 domains using that IP. > > Do you mean 3 domain names with DNS address ressource records pointing > to that address ? Yes, >> I tried to use iptables' "string" match in the nat table to redirect >> incoming packets to the LAN IP of the computer indicated by the domain >> name. "-m string --string DOMAIN.NAME -j DNAT" in PREROUTING doesn't >> work; the domain string is not matched. > > That cannot work. The nat chains, where you can use the DNAT target, see > only the first packet (SYN) of a connection, which does not contain any > data. The target host name is contained is a subsequent packet, but then > it is too late, the NAT mapping cannot be changed. > >> The only required services for each of these domains are ftp and http. >> More specifically, domain A needs to provide ftp and http, domain B >> needs ftp, http, rsync & ssh; domain C needs those and more. > > For HTTP 1.1, you need a reverse proxy. For other protocols such as FTP, > the only "solution" is to use a different address or port with each > domain name : unlike HTTP, these protocols do not advertise the targed > host name in the payload. > >> Am I doomed to having these services all be on the Slackware box? > > The problem would be the same on a single box. No, it isn't. I can set up Apache for any number of domains. Same with the ftp server. SSH can be run on different ports so there can be 3 running instances... -- buck
[toc] | [prev] | [next] | [standalone]
| From | Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> |
|---|---|
| Date | 2012-03-15 23:05 +0100 |
| Message-ID | <jjtp2f$p13$1@saria.nerim.net> |
| In reply to | #1173 |
buck a écrit : > Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> wrote : > >> buck a écrit : >> >>> Am I doomed to having these services all be on the Slackware box? >> >> The problem would be the same on a single box. > > No, it isn't. Yes, it is. > I can set up Apache for any number of domains. You can also set a reverse HTTP proxy for any number of domains, forwarding each domain to a server on a different machine. > Same with the ftp server. No, FTP servers do not have domains. Unlike HTTP, you cannot connect to an FTP server and ask for a specific domain. You cannot run several servers listening on the same port and address either. > SSH can be run on different ports so there can > be 3 running instances... You can also forward three different ports to three different SSH servers. As I wrote, the problem is the same.
[toc] | [prev] | [next] | [standalone]
| From | buck <buck@private.mil> |
|---|---|
| Date | 2012-03-16 18:29 +0000 |
| Message-ID | <jk00r002s2b@news3.newsguy.com> |
| In reply to | #1174 |
>> Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> wrote : >> Same with the ftp server. > > No, FTP servers do not have domains. Unlike HTTP, you cannot connect > to an FTP server and ask for a specific domain. You cannot run several > servers listening on the same port and address either. Perhaps you should check out ncftp, because it certainly can and does handle multiple domains. Right now it is serving domains A and C. -- buck
[toc] | [prev] | [next] | [standalone]
| From | Chris Davies <chris-usenet@roaima.co.uk> |
|---|---|
| Date | 2012-03-16 21:09 +0000 |
| Message-ID | <spmc39xj1v.ln2@news.roaima.co.uk> |
| In reply to | #1179 |
buck <buck@private.mil> wrote: > Perhaps you should check out ncftp, because it certainly can and does > handle multiple domains. Right now it is serving domains A and C. This from the NcFTP FAQ (http://www.ncftp.com/ncftpd/doc/faq/func.html): Is it possible to have 2 virtual hosts with only one IP address? No. This is due to a limitation of the FTP protocol. [...] So I have to assume that your domains A and C are on separate IP addresses, which seems to be outside the scope of your original question (you mentioned wanting to run multiple services from a single WAN IP address). Chris
[toc] | [prev] | [next] | [standalone]
| From | unruh <unruh@invalid.ca> |
|---|---|
| Date | 2012-03-16 23:42 +0000 |
| Message-ID | <HdQ8r.503$532.75@newsfe14.iad> |
| In reply to | #1181 |
On 2012-03-16, Chris Davies <chris-usenet@roaima.co.uk> wrote: > buck <buck@private.mil> wrote: >> Perhaps you should check out ncftp, because it certainly can and does >> handle multiple domains. Right now it is serving domains A and C. > > This from the NcFTP FAQ (http://www.ncftp.com/ncftpd/doc/faq/func.html): > > Is it possible to have 2 virtual hosts with only one IP address? > > No. This is due to a limitation of the FTP protocol. [...] > > So I have to assume that your domains A and C are on separate IP > addresses, which seems to be outside the scope of your original > question (you mentioned wanting to run multiple services from a single > WAN IP address). Or you could have your two servers running on two different ports. Then you use the "open" command in ftp to go to the two different ports on the same IP address. On ncftp you can specify the port directly with the -P option. One address, two ftp servers on two ports. > > Chris
[toc] | [prev] | [next] | [standalone]
| From | Chris Davies <chris-usenet@roaima.co.uk> |
|---|---|
| Date | 2012-03-17 09:30 +0000 |
| Message-ID | <v62e39xc0f.ln2@news.roaima.co.uk> |
| In reply to | #1182 |
unruh <unruh@invalid.ca> wrote: > Or you could have your two servers running on two different ports. Which is what I suggested about two comments up the thread. Chris
[toc] | [prev] | [next] | [standalone]
| From | buck <buck@private.mil> |
|---|---|
| Date | 2012-03-17 17:47 +0000 |
| Message-ID | <jk2inm016vg@news4.newsguy.com> |
| In reply to | #1181 |
Chris Davies <chris-usenet@roaima.co.uk> wrote in news:spmc39xj1v.ln2 @news.roaima.co.uk: > buck <buck@private.mil> wrote: >> Perhaps you should check out ncftp, because it certainly can and does >> handle multiple domains. Right now it is serving domains A and C. > > This from the NcFTP FAQ (http://www.ncftp.com/ncftpd/doc/faq/func.html): > > Is it possible to have 2 virtual hosts with only one IP address? > > No. This is due to a limitation of the FTP protocol. [...] > > So I have to assume that your domains A and C are on separate IP > addresses, which seems to be outside the scope of your original > question (you mentioned wanting to run multiple services from a single > WAN IP address). > > Chris Chris, Please ftp chsoft.biz (domain B) from a command prompt. Login as ftp; I use PW "buck@", so it'd be nice if you'd use some other short password... The login timeout is set very short (30 seconds), so don't dick around. Idle timout is 300. 'ls' should show you a "zip" directory, among others. 'cd pub' followed by 'ls' should show a "vamsql_fund_data" directory, among others. If you feel generous, please post a screen shot or 2, which will help me test this from outside. I haven't done that yet. Here's the deal. Domain C has a WAN IP but domain B has IP 192.168.223.127. Note that this is exactly what I wanted to accomplish for http, rsync and ssh, but (if it works for you), ftp is the only service that is actually "on" a separate computer. Also note that ncftpd is bound to the WAN IP, but by setting domain.cf to use the LAN IP of domain B (~.127), the files on that computer are made available. -- buck
[toc] | [prev] | [next] | [standalone]
| From | Chris Davies <chris-usenet@roaima.co.uk> |
|---|---|
| Date | 2012-03-18 09:14 +0000 |
| Message-ID | <vklg39xduf.ln2@news.roaima.co.uk> |
| In reply to | #1184 |
buck <buck@private.mil> wrote: > Here's the deal. Domain C has a WAN IP but domain B has IP > 192.168.223.127. Right. So different FTP services are bound to different IP addresses on the same server. This is not what I understood from your original posting. You cannot have two (or more) different FTP "domains" bound to the same port/IP address combination on the same server. However, if any one of those three items is different you can run distinct servers (or services). The same is true for any service. Chris
[toc] | [prev] | [next] | [standalone]
| From | Chris Davies <chris-usenet@roaima.co.uk> |
|---|---|
| Date | 2012-03-15 22:16 +0000 |
| Message-ID | <6a6a39xaqu.ln2@news.roaima.co.uk> |
| In reply to | #1169 |
buck <buck@private.mil> wrote: > The only required services for each of these domains are ftp and http. > More specifically, domain A needs to provide ftp and http, domain B > needs ftp, http, rsync & ssh; domain C needs those and more. 1. You can use apache on your slackware box to proxy HTTP (tcp/80) requests targetted at different domains but the same IP address to different appropriate web servers. Look up virtual hosts and the NameVirtualHost directive. 1b. You cannot run two or more domains requiring HTTPS on the same external IP address. 2. You cannot have two different FTP servers on the same single external IP address. 3. You cannot have two different Rsync servers on the same single IP address. 4. You cannot have two different SSH servers on the same single IP address. Actually, you can do 1b, 2, 3, and 4 if you are prepared to sacrifice use of the standard service ports (e.g. you run SSH on port 22 for server X, and on port 10022 for server Y, and on port 20022 for server Z). But that may not be acceptable. Hope this helps, Chris
[toc] | [prev] | [next] | [standalone]
| From | Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> |
|---|---|
| Date | 2012-03-16 00:35 +0100 |
| Message-ID | <jjtuce$r00$1@saria.nerim.net> |
| In reply to | #1175 |
Chris Davies a écrit : > > 1b. You cannot run two or more domains requiring HTTPS on the same > external IP address. Actually this is possible with a certificate which covers multiple names, or if both the client and the server support the SNI (Server Name Indication) TLS/SSL extension. See <http://en.wikipedia.org/wiki/Server_Name_Indication>
[toc] | [prev] | [next] | [standalone]
| From | Chris Davies <chris-usenet@roaima.co.uk> |
|---|---|
| Date | 2012-03-16 09:03 +0000 |
| Message-ID | <57cb39x88d.ln2@news.roaima.co.uk> |
| In reply to | #1176 |
Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> wrote: > Actually this is possible with a certificate which covers multiple > names, or if both the client and the server support the SNI (Server Name > Indication) TLS/SSL extension. > See <http://en.wikipedia.org/wiki/Server_Name_Indication> Agreed in principle, but I've had nothing but problems in the real world with this kind of scenario. Chris
[toc] | [prev] | [next] | [standalone]
| From | Tauno Voipio <tauno.voipio@notused.fi.invalid> |
|---|---|
| Date | 2012-03-16 09:11 +0200 |
| Message-ID | <jjup3q$hus$2@dont-email.me> |
| In reply to | #1175 |
On 16.3.12 12:16 , Chris Davies wrote: > buck<buck@private.mil> wrote: >> The only required services for each of these domains are ftp and http. >> More specifically, domain A needs to provide ftp and http, domain B >> needs ftp, http, rsync& ssh; domain C needs those and more. > > 1. You can use apache on your slackware box to proxy HTTP (tcp/80) > requests targetted at different domains but the same IP address to > different appropriate web servers. Look up virtual hosts and the > NameVirtualHost directive. > > 1b. You cannot run two or more domains requiring HTTPS on the same > external IP address. > > 2. You cannot have two different FTP servers on the same single external > IP address. > > 3. You cannot have two different Rsync servers on the same single > IP address. > > 4. You cannot have two different SSH servers on the same single IP > address. > > Actually, you can do 1b, 2, 3, and 4 if you are prepared to sacrifice use > of the standard service ports (e.g. you run SSH on port 22 for server X, > and on port 10022 for server Y, and on port 20022 for server Z). But > that may not be acceptable. > > Hope this helps, > Chris Also, FTP is a PITA for any address translation, as it uses two ports, and the NAT box has to know that both need to be translated. It is pretty sure that FTP on a non-standard port does not pass NAT handling. -- Tauno Voipio
[toc] | [prev] | [next] | [standalone]
| From | buck <buck@private.mil> |
|---|---|
| Date | 2012-03-16 18:41 +0000 |
| Message-ID | <jk01hk02sq5@news3.newsguy.com> |
| In reply to | #1177 |
Tauno Voipio <tauno.voipio@notused.fi.invalid> wrote in news:jjup3q$hus$2@dont-email.me: > Also, FTP is a PITA for any address translation, as it uses two ports, > and the NAT box has to know that both need to be translated. It is > pretty sure that FTP on a non-standard port does not pass NAT > handling. Regardless, the answer to my question is an emphatic NO, for the reason Pascal gave in the first reply to this thread. By the time when the domain is known, it is too late to NAT it. -- buck
[toc] | [prev] | [standalone]
Back to top | Article view | comp.os.linux.networking
csiph-web