Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.networking > #1169 > unrolled thread

multi domains, single IP

Started bybuck <buck@private.mil>
First post2012-03-15 15:45 +0000
Last post2012-03-16 18:41 +0000
Articles 15 — 5 participants

Back to article view | Back to comp.os.linux.networking


Contents

  multi domains, single IP buck <buck@private.mil> - 2012-03-15 15:45 +0000
    Re: multi domains, single IP Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-03-15 20:32 +0100
      Re: multi domains, single IP buck <buck@private.mil> - 2012-03-15 20:54 +0000
        Re: multi domains, single IP Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-03-15 23:05 +0100
          Re: multi domains, single IP buck <buck@private.mil> - 2012-03-16 18:29 +0000
            Re: multi domains, single IP Chris Davies <chris-usenet@roaima.co.uk> - 2012-03-16 21:09 +0000
              Re: multi domains, single IP unruh <unruh@invalid.ca> - 2012-03-16 23:42 +0000
                Re: multi domains, single IP Chris Davies <chris-usenet@roaima.co.uk> - 2012-03-17 09:30 +0000
              Re: multi domains, single IP buck <buck@private.mil> - 2012-03-17 17:47 +0000
                Re: multi domains, single IP Chris Davies <chris-usenet@roaima.co.uk> - 2012-03-18 09:14 +0000
    Re: multi domains, single IP Chris Davies <chris-usenet@roaima.co.uk> - 2012-03-15 22:16 +0000
      Re: multi domains, single IP Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-03-16 00:35 +0100
        Re: multi domains, single IP Chris Davies <chris-usenet@roaima.co.uk> - 2012-03-16 09:03 +0000
      Re: multi domains, single IP Tauno Voipio <tauno.voipio@notused.fi.invalid> - 2012-03-16 09:11 +0200
        Re: multi domains, single IP buck <buck@private.mil> - 2012-03-16 18:41 +0000

#1169 — multi domains, single IP

Frombuck <buck@private.mil>
Date2012-03-15 15:45 +0000
Subjectmulti domains, single IP
Message-ID<jjt2q702p29@news6.newsguy.com>
I know it is possible to do this on a single computer.  What I need to 
know is if it is possible to have each domain be specific to its own 
computer, and how to accomplish that.

There is only one WAN IP address available.

The setup is that one (Slackware) box's eth1 is connected to the ISP 
(WAN) while its eth0 is connected to a switch (LAN, with 192.168 IPs).  
Obviously, only one WAN connection is possible.  At this time, there 
are 3 domains using that IP.

I tried to use iptables' "string" match in the nat table to redirect 
incoming packets to the LAN IP of the computer indicated by the domain 
name.  "-m string --string DOMAIN.NAME -j DNAT" in PREROUTING doesn't 
work; the domain string is not matched.

The only required services for each of these domains are ftp and http.  
More specifically, domain A needs to provide ftp and http, domain B 
needs ftp, http, rsync & ssh; domain C needs those and more.

Am I doomed to having these services all be on the Slackware box?
--
buck

[toc] | [next] | [standalone]


#1172

FromPascal Hambourg <boite-a-spam@plouf.fr.eu.org>
Date2012-03-15 20:32 +0100
Message-ID<jjtg50$lmp$1@saria.nerim.net>
In reply to#1169
Hello,

buck a écrit :
> I know it is possible to do this on a single computer.  What I need to 
> know is if it is possible to have each domain be specific to its own 
> computer, and how to accomplish that.
> 
> There is only one WAN IP address available.
> 
> The setup is that one (Slackware) box's eth1 is connected to the ISP 
> (WAN) while its eth0 is connected to a switch (LAN, with 192.168 IPs).  
> Obviously, only one WAN connection is possible. 

What do you mean ?

> At this time, there are 3 domains using that IP.

Do you mean 3 domain names with DNS address ressource records pointing
to that address ?

> I tried to use iptables' "string" match in the nat table to redirect 
> incoming packets to the LAN IP of the computer indicated by the domain 
> name.  "-m string --string DOMAIN.NAME -j DNAT" in PREROUTING doesn't 
> work; the domain string is not matched.

That cannot work. The nat chains, where you can use the DNAT target, see
only the first packet (SYN) of a connection, which does not contain any
data. The target host name is contained is a subsequent packet, but then
it is too late, the NAT mapping cannot be changed.

> The only required services for each of these domains are ftp and http.  
> More specifically, domain A needs to provide ftp and http, domain B 
> needs ftp, http, rsync & ssh; domain C needs those and more.

For HTTP 1.1, you need a reverse proxy. For other protocols such as FTP,
the only "solution" is to use a different address or port with each
domain name : unlike HTTP, these protocols do not advertise the targed
host name in the payload.

> Am I doomed to having these services all be on the Slackware box?

The problem would be the same on a single box.

[toc] | [prev] | [next] | [standalone]


#1173

Frombuck <buck@private.mil>
Date2012-03-15 20:54 +0000
Message-ID<jjtktr02rrv@news4.newsguy.com>
In reply to#1172
Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> wrote in news:jjtg50
$lmp$1@saria.nerim.net:

> Hello,
> 
> buck a écrit :
>> I know it is possible to do this on a single computer.  What I need 
to 
>> know is if it is possible to have each domain be specific to its 
own 
>> computer, and how to accomplish that.
>> 
>> There is only one WAN IP address available.
>> 
>> The setup is that one (Slackware) box's eth1 is connected to the 
ISP 
>> (WAN) while its eth0 is connected to a switch (LAN, with 192.168 
IPs).  
>> Obviously, only one WAN connection is possible. 
> 
> What do you mean ?

It is not possible to connect more than one computer to the WAN.  
Conflicts occur otherwise; the OS complains that more than one 
computer has the same IP.

 >> At this time, there are 3 domains using that IP.
> 
> Do you mean 3 domain names with DNS address ressource records 
pointing
> to that address ?

Yes,
 
>> I tried to use iptables' "string" match in the nat table to 
redirect 
>> incoming packets to the LAN IP of the computer indicated by the 
domain 
>> name.  "-m string --string DOMAIN.NAME -j DNAT" in PREROUTING 
doesn't 
>> work; the domain string is not matched.
> 
> That cannot work. The nat chains, where you can use the DNAT target, 
see
> only the first packet (SYN) of a connection, which does not contain 
any
> data. The target host name is contained is a subsequent packet, but 
then
> it is too late, the NAT mapping cannot be changed.
> 
>> The only required services for each of these domains are ftp and 
http.  
>> More specifically, domain A needs to provide ftp and http, domain B 
>> needs ftp, http, rsync & ssh; domain C needs those and more.
> 
> For HTTP 1.1, you need a reverse proxy. For other protocols such as 
FTP,
> the only "solution" is to use a different address or port with each
> domain name : unlike HTTP, these protocols do not advertise the 
targed
> host name in the payload.
> 
>> Am I doomed to having these services all be on the Slackware box?
> 
> The problem would be the same on a single box.

No, it isn't.  I can set up Apache for any number of domains.  Same 
with the ftp server.  SSH can be run on different ports so there can 
be 3 running instances...
--
buck 

[toc] | [prev] | [next] | [standalone]


#1174

FromPascal Hambourg <boite-a-spam@plouf.fr.eu.org>
Date2012-03-15 23:05 +0100
Message-ID<jjtp2f$p13$1@saria.nerim.net>
In reply to#1173
buck a écrit :
> Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> wrote :
> 
>> buck a écrit :
>>
>>> Am I doomed to having these services all be on the Slackware box?
>>
>> The problem would be the same on a single box.
> 
> No, it isn't.

Yes, it is.

> I can set up Apache for any number of domains.

You can also set a reverse HTTP proxy for any number of domains,
forwarding each domain to a server on a different machine.

> Same with the ftp server.

No, FTP servers do not have domains. Unlike HTTP, you cannot connect to
an FTP server and ask for a specific domain. You cannot run several
servers listening on the same port and address either.

> SSH can be run on different ports so there can 
> be 3 running instances...

You can also forward three different ports to three different SSH servers.

As I wrote, the problem is the same.

[toc] | [prev] | [next] | [standalone]


#1179

Frombuck <buck@private.mil>
Date2012-03-16 18:29 +0000
Message-ID<jk00r002s2b@news3.newsguy.com>
In reply to#1174
>> Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> wrote :
>> Same with the ftp server.
> 
> No, FTP servers do not have domains. Unlike HTTP, you cannot connect
> to an FTP server and ask for a specific domain. You cannot run several
> servers listening on the same port and address either.

Perhaps you should check out ncftp, because it certainly can and does 
handle multiple domains.  Right now it is serving domains A and C.
--
buck

[toc] | [prev] | [next] | [standalone]


#1181

FromChris Davies <chris-usenet@roaima.co.uk>
Date2012-03-16 21:09 +0000
Message-ID<spmc39xj1v.ln2@news.roaima.co.uk>
In reply to#1179
buck <buck@private.mil> wrote:
> Perhaps you should check out ncftp, because it certainly can and does 
> handle multiple domains. Right now it is serving domains A and C.

This from the NcFTP FAQ (http://www.ncftp.com/ncftpd/doc/faq/func.html):

  Is it possible to have 2 virtual hosts with only one IP address?

  No. This is due to a limitation of the FTP protocol. [...]

So I have to assume that your domains A and C are on separate IP
addresses, which seems to be outside the scope of your original
question (you mentioned wanting to run multiple services from a single
WAN IP address).

Chris

[toc] | [prev] | [next] | [standalone]


#1182

Fromunruh <unruh@invalid.ca>
Date2012-03-16 23:42 +0000
Message-ID<HdQ8r.503$532.75@newsfe14.iad>
In reply to#1181
On 2012-03-16, Chris Davies <chris-usenet@roaima.co.uk> wrote:
> buck <buck@private.mil> wrote:
>> Perhaps you should check out ncftp, because it certainly can and does 
>> handle multiple domains. Right now it is serving domains A and C.
>
> This from the NcFTP FAQ (http://www.ncftp.com/ncftpd/doc/faq/func.html):
>
>   Is it possible to have 2 virtual hosts with only one IP address?
>
>   No. This is due to a limitation of the FTP protocol. [...]
>
> So I have to assume that your domains A and C are on separate IP
> addresses, which seems to be outside the scope of your original
> question (you mentioned wanting to run multiple services from a single
> WAN IP address).

Or you could have  your two servers running on two different ports. Then
you use the "open" command in ftp to go to the two different ports on
the same IP address. 
On ncftp you can specify the port directly with the -P option.
One address, two ftp servers on two ports. 


>
> Chris

[toc] | [prev] | [next] | [standalone]


#1183

FromChris Davies <chris-usenet@roaima.co.uk>
Date2012-03-17 09:30 +0000
Message-ID<v62e39xc0f.ln2@news.roaima.co.uk>
In reply to#1182
unruh <unruh@invalid.ca> wrote:
> Or you could have  your two servers running on two different ports.

Which is what I suggested about two comments up the thread.
Chris

[toc] | [prev] | [next] | [standalone]


#1184

Frombuck <buck@private.mil>
Date2012-03-17 17:47 +0000
Message-ID<jk2inm016vg@news4.newsguy.com>
In reply to#1181
Chris Davies <chris-usenet@roaima.co.uk> wrote in news:spmc39xj1v.ln2
@news.roaima.co.uk:

> buck <buck@private.mil> wrote:
>> Perhaps you should check out ncftp, because it certainly can and 
does 
>> handle multiple domains. Right now it is serving domains A and C.
> 
> This from the NcFTP FAQ 
(http://www.ncftp.com/ncftpd/doc/faq/func.html):
> 
>   Is it possible to have 2 virtual hosts with only one IP address?
> 
>   No. This is due to a limitation of the FTP protocol. [...]
> 
> So I have to assume that your domains A and C are on separate IP
> addresses, which seems to be outside the scope of your original
> question (you mentioned wanting to run multiple services from a 
single
> WAN IP address).
> 
> Chris

Chris,
Please ftp chsoft.biz (domain B) from a command prompt.  Login as ftp; 
I use PW "buck@", so it'd be nice if you'd use some other short 
password...  The login timeout is set very short (30 seconds), so 
don't dick around.  Idle timout is 300.

'ls' should show you a "zip" directory, among others.

'cd pub' followed by 'ls' should show a "vamsql_fund_data" directory, 
among others.

If you feel generous, please post a screen shot or 2, which will help 
me test this from outside.  I haven't done that yet.

Here's the deal.  Domain C has a WAN IP but domain B has IP 
192.168.223.127.  Note that this is exactly what I wanted to 
accomplish for http, rsync and ssh, but (if it works for you), ftp is 
the only service that is actually "on" a separate computer.  Also note 
that ncftpd is bound to the WAN IP, but by setting domain.cf to use 
the LAN IP of domain B (~.127), the files on that computer are made 
available.
--
buck 

[toc] | [prev] | [next] | [standalone]


#1185

FromChris Davies <chris-usenet@roaima.co.uk>
Date2012-03-18 09:14 +0000
Message-ID<vklg39xduf.ln2@news.roaima.co.uk>
In reply to#1184
buck <buck@private.mil> wrote:
> Here's the deal.  Domain C has a WAN IP but domain B has IP 
> 192.168.223.127.

Right. So different FTP services are bound to different IP addresses on
the same server. This is not what I understood from your original posting.

You cannot have two (or more) different FTP "domains" bound to the same
port/IP address combination on the same server. However, if any one of
those three items is different you can run distinct servers (or
services). The same is true for any service.

Chris

[toc] | [prev] | [next] | [standalone]


#1175

FromChris Davies <chris-usenet@roaima.co.uk>
Date2012-03-15 22:16 +0000
Message-ID<6a6a39xaqu.ln2@news.roaima.co.uk>
In reply to#1169
buck <buck@private.mil> wrote:
> The only required services for each of these domains are ftp and http.  
> More specifically, domain A needs to provide ftp and http, domain B 
> needs ftp, http, rsync & ssh; domain C needs those and more.

1. You can use apache on your slackware box to proxy HTTP (tcp/80)
requests targetted at different domains but the same IP address to
different appropriate web servers. Look up virtual hosts and the
NameVirtualHost directive.

1b. You cannot run two or more domains requiring HTTPS on the same
external IP address.

2. You cannot have two different FTP servers on the same single external
IP address.

3. You cannot have two different Rsync servers on the same single
IP address.

4. You cannot have two different SSH servers on the same single IP
address.

Actually, you can do 1b, 2, 3, and 4 if you are prepared to sacrifice use
of the standard service ports (e.g. you run SSH on port 22 for server X,
and on port 10022 for server Y, and on port 20022 for server Z). But
that may not be acceptable.

Hope this helps,
Chris

[toc] | [prev] | [next] | [standalone]


#1176

FromPascal Hambourg <boite-a-spam@plouf.fr.eu.org>
Date2012-03-16 00:35 +0100
Message-ID<jjtuce$r00$1@saria.nerim.net>
In reply to#1175
Chris Davies a écrit :
> 
> 1b. You cannot run two or more domains requiring HTTPS on the same
> external IP address.

Actually this is possible with a certificate which covers multiple
names, or if both the client and the server support the SNI (Server Name
Indication) TLS/SSL extension.
See <http://en.wikipedia.org/wiki/Server_Name_Indication>

[toc] | [prev] | [next] | [standalone]


#1178

FromChris Davies <chris-usenet@roaima.co.uk>
Date2012-03-16 09:03 +0000
Message-ID<57cb39x88d.ln2@news.roaima.co.uk>
In reply to#1176
Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> wrote:
> Actually this is possible with a certificate which covers multiple
> names, or if both the client and the server support the SNI (Server Name
> Indication) TLS/SSL extension.
> See <http://en.wikipedia.org/wiki/Server_Name_Indication>

Agreed in principle, but I've had nothing but problems in the real world
with this kind of scenario.

Chris

[toc] | [prev] | [next] | [standalone]


#1177

FromTauno Voipio <tauno.voipio@notused.fi.invalid>
Date2012-03-16 09:11 +0200
Message-ID<jjup3q$hus$2@dont-email.me>
In reply to#1175
On 16.3.12 12:16 , Chris Davies wrote:
> buck<buck@private.mil>  wrote:
>> The only required services for each of these domains are ftp and http.
>> More specifically, domain A needs to provide ftp and http, domain B
>> needs ftp, http, rsync&  ssh; domain C needs those and more.
>
> 1. You can use apache on your slackware box to proxy HTTP (tcp/80)
> requests targetted at different domains but the same IP address to
> different appropriate web servers. Look up virtual hosts and the
> NameVirtualHost directive.
>
> 1b. You cannot run two or more domains requiring HTTPS on the same
> external IP address.
>
> 2. You cannot have two different FTP servers on the same single external
> IP address.
>
> 3. You cannot have two different Rsync servers on the same single
> IP address.
>
> 4. You cannot have two different SSH servers on the same single IP
> address.
>
> Actually, you can do 1b, 2, 3, and 4 if you are prepared to sacrifice use
> of the standard service ports (e.g. you run SSH on port 22 for server X,
> and on port 10022 for server Y, and on port 20022 for server Z). But
> that may not be acceptable.
>
> Hope this helps,
> Chris


Also, FTP is a PITA for any address translation, as it uses two ports,
and the NAT box has to know that both need to be translated. It is
pretty sure that FTP on a non-standard port does not pass NAT handling.

-- 

Tauno Voipio

[toc] | [prev] | [next] | [standalone]


#1180

Frombuck <buck@private.mil>
Date2012-03-16 18:41 +0000
Message-ID<jk01hk02sq5@news3.newsguy.com>
In reply to#1177
Tauno Voipio <tauno.voipio@notused.fi.invalid> wrote in
news:jjup3q$hus$2@dont-email.me: 

> Also, FTP is a PITA for any address translation, as it uses two ports,
> and the NAT box has to know that both need to be translated. It is
> pretty sure that FTP on a non-standard port does not pass NAT
> handling. 

Regardless, the answer to my question is an emphatic NO, for the reason 
Pascal gave in the first reply to this thread.  By the time when the 
domain is known, it is too late to NAT it.
--
buck

[toc] | [prev] | [standalone]


Back to top | Article view | comp.os.linux.networking


csiph-web