Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #247859 > unrolled thread
| Started by | Tom Browder <tom.browder@gmail.com> |
|---|---|
| First post | 2022-05-03 21:50 +0200 |
| Last post | 2022-05-07 10:00 +0200 |
| Articles | 20 on this page of 26 — 12 participants |
Back to article view | Back to linux.debian.user
Networking book recommendation Tom Browder <tom.browder@gmail.com> - 2022-05-03 21:50 +0200
Re: Networking book recommendation john doe <johndoe65534@mail.com> - 2022-05-03 22:20 +0200
Re: Networking book recommendation Jeremy Ardley <jeremy@ardley.org> - 2022-05-03 22:30 +0200
Re: Networking book recommendation <tomas@tuxteam.de> - 2022-05-04 07:00 +0200
Re: Networking book recommendation Jeremy Ardley <jeremy@ardley.org> - 2022-05-04 08:00 +0200
Re: Networking book recommendation Tom Browder <tom.browder@gmail.com> - 2022-05-03 22:40 +0200
Re: Networking book recommendation Dan Ritter <dsr@randomstring.org> - 2022-05-03 23:10 +0200
Re: Networking book recommendation john doe <johndoe65534@mail.com> - 2022-05-04 18:10 +0200
Re: Networking book recommendation Tom Browder <tom.browder@gmail.com> - 2022-05-05 16:40 +0200
Re: Networking book recommendation john doe <johndoe65534@mail.com> - 2022-05-05 21:40 +0200
Re: Networking book recommendation David Christensen <dpchrist@holgerdanske.com> - 2022-05-05 23:10 +0200
Re: Networking book recommendation Tom Browder <tom.browder@gmail.com> - 2022-05-06 00:40 +0200
Re: Networking book recommendation Celejar <celejar@gmail.com> - 2022-05-06 03:50 +0200
Re: Networking book recommendation Dan Ritter <dsr@randomstring.org> - 2022-05-06 04:00 +0200
Re: Networking book recommendation john doe <johndoe65534@mail.com> - 2022-05-06 09:00 +0200
Re: Networking book recommendation David Christensen <dpchrist@holgerdanske.com> - 2022-05-05 22:50 +0200
Re: Networking book recommendation Charles Curley <charlescurley@charlescurley.com> - 2022-05-03 22:40 +0200
Re: Networking book recommendation Tixy <tixy@yxit.co.uk> - 2022-05-03 23:00 +0200
Re: Networking book recommendation Dan Ritter <dsr@randomstring.org> - 2022-05-03 23:00 +0200
Re: Networking book recommendation Tom Browder <tom.browder@gmail.com> - 2022-05-03 23:20 +0200
Re: Networking book recommendation Greg Wooledge <greg@wooledge.org> - 2022-05-03 23:30 +0200
Re: Networking book recommendation Tom Browder <tom.browder@gmail.com> - 2022-05-03 23:40 +0200
Re: Networking book recommendation Bob Weber <bobrweber@gmail.com> - 2022-05-04 00:30 +0200
Re: Networking book recommendation Tom Browder <tom.browder@gmail.com> - 2022-05-04 01:40 +0200
Re: Networking book recommendation David Christensen <dpchrist@holgerdanske.com> - 2022-05-04 01:50 +0200
Re: Networking book recommendation "Rick Thomas" <rick.thomas@pobox.com> - 2022-05-07 10:00 +0200
Page 1 of 2 [1] 2 Next page →
| From | Tom Browder <tom.browder@gmail.com> |
|---|---|
| Date | 2022-05-03 21:50 +0200 |
| Subject | Networking book recommendation |
| Message-ID | <Ej6GZ-cZwJ-3@gated-at.bofh.it> |
[Multipart message — attachments visible in raw view] — view raw
I'm about to sign up for a fixed IPv4 address to my home. I know a bit about setting up simple internal networks, but want to make sure I'm doing it all correctly and securely. Does anyone have a good book they recommend for such use? Thanks. -Tom
[toc] | [next] | [standalone]
| From | john doe <johndoe65534@mail.com> |
|---|---|
| Date | 2022-05-03 22:20 +0200 |
| Message-ID | <Ej7a1-d01z-1@gated-at.bofh.it> |
| In reply to | #247859 |
On 5/3/2022 9:42 PM, Tom Browder wrote: > I'm about to sign up for a fixed IPv4 address to my home. I know a bit > about setting up simple internal networks, but want to make sure I'm > doing it all correctly and securely. Does anyone have a good book they > recommend for such use? > What do you mean by "correctly and securly", the networking is never secure. Depending on what you need, you might want firewall ... That also brings the question, why do you need a static IPv4 address? -- John Doe
[toc] | [prev] | [next] | [standalone]
| From | Jeremy Ardley <jeremy@ardley.org> |
|---|---|
| Date | 2022-05-03 22:30 +0200 |
| Message-ID | <Ej7jH-d04N-5@gated-at.bofh.it> |
| In reply to | #247861 |
[Multipart message — attachments visible in raw view] — view raw
On 4/5/22 4:18 am, john doe wrote: > > What do you mean by "correctly and securly", the networking is never > secure. > Depending on what you need, you might want firewall ... > > That also brings the question, why do you need a static IPv4 address? > > For almost all domestic installations a single static IPv4 address is managed by the router and used to NAT internal addresses. NAT in itself provides quite good security because internal hosts can't be scanned by attackers. If the router is a normal commercial router it will manage the internal network and will itself have very few vulnerabilities If the static IPv4 address is to be used to provide a public service then it's usual to forward inbound connections to an internal host to provide that service. That forwarding is usually router specific. -- Jeremy
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2022-05-04 07:00 +0200 |
| Message-ID | <Ejfhf-d5eH-1@gated-at.bofh.it> |
| In reply to | #247862 |
[Multipart message — attachments visible in raw view] — view raw
On Wed, May 04, 2022 at 04:27:52AM +0800, Jeremy Ardley wrote: [...] > [...] NAT in itself > provides quite good security because internal hosts can't be scanned by > attackers. Uh, oh. I think general opinion these days disagree with this statement strongly (see e.g. [1], but this has been rough consensus since at least the 2000s). That said, even "normal" hands-off firewalls don't help against the most widespread threats of these days: malicious actors that are located inside your network: be it some random javascript running in your browser, a printer phoning home or your so-called smart TV. All of those will connect to outside things from the inside, and a no-trouble hands-off firewall is configured to allow just that. The known attacks against NAT dwindle given the above-mentioned cornucopia :-) Don't get me started on things like UPMP's NAT-PMP [2] which are explicitily designed for clients to punch holes into the firewall. Cheers [1] https://security.stackexchange.com/questions/8772/how-important-is-nat-as-a-security-layer [2] https://en.wikipedia.org/wiki/NAT_Port_Mapping_Protocol -- t
[toc] | [prev] | [next] | [standalone]
| From | Jeremy Ardley <jeremy@ardley.org> |
|---|---|
| Date | 2022-05-04 08:00 +0200 |
| Message-ID | <Ejgdj-d5U6-5@gated-at.bofh.it> |
| In reply to | #247884 |
[Multipart message — attachments visible in raw view] — view raw
On 4/5/22 12:57 pm, tomas@tuxteam.de wrote: > On Wed, May 04, 2022 at 04:27:52AM +0800, Jeremy Ardley wrote: > > [...] > >> [...] NAT in itself >> provides quite good security because internal hosts can't be scanned by >> attackers. > Uh, oh. I think general opinion these days disagree with this > statement strongly (see e.g. [1], but this has been rough > consensus since at least the 2000s). Your consensus is 20 years old. Times move Natural evolution has developed standard features in routers that out of the box are 'good enough' for SOHO implementations. That is when you plug it in and connect to your home LAN you can reasonably expect your LAN won't be compromised in 5 minutes or even 5 years of persistent attacks. The only problem is when the enthusiastic owner starts opening ports to allow internal mail or web, or even just to run some games. This problem will also occur when you have the latest fancy dandy firewall. It is users who are insecure, not NAT or routers as such. More interesting is IPv6 which many ISPs now offer. Modern routers know about Prefix delegation and all your windows hosts will automatically pick up IPv6 Addresses. These are 'raw' on the internet, no NAT involved. It will depend on your router firewall on how well protected you are. In the IPv6 case, modern Windows machines all have inbuilt firewalls that work reasonably well. Linux systems are variable in firewall configuration and may not be as well protected. I run my own Armbian dual homed router that does the IPv6 stuff and I have a reasonable set of ip6tables rules to allow specific hosts to provide IPv6 services on well known addresses (ie in DNS) but at the same time protect most other hosts from any unsolicited IPv6 Traffic. If I was still in the 90s I'd set up a DMZ blah blah. Now I just expose services on the router using HA proxy for IPv4 Stuff and specific rules for IPv6. I also run a postfix instance on the router for IPv4 connectivity. Jeremy
[toc] | [prev] | [next] | [standalone]
| From | Tom Browder <tom.browder@gmail.com> |
|---|---|
| Date | 2022-05-03 22:40 +0200 |
| Message-ID | <Ej7tn-d07E-1@gated-at.bofh.it> |
| In reply to | #247861 |
[Multipart message — attachments visible in raw view] — view raw
On Tue, May 3, 2022 at 15:18 john doe <johndoe65534@mail.com> wrote: > On 5/3/2022 9:42 PM, Tom Browder wrote: > > I'm about to sign up for a fixed IPv4 address to my home. I know a bit > > about setting up simple internal networks, but want to make sure I'm > > doing it all correctly and securely. Does anyone have a good book they > > recommend for such use? > > > > What do you mean by "correctly and securly", the networking is never > secure. Thanks, I didn't know that. Depending on what you need, you might want firewall ... I'm considering HaProxy downsteam from the router. That also brings the question, why do you need a static IPv4 address? I'm moving my webservers inside. Thanks. -Tom
[toc] | [prev] | [next] | [standalone]
| From | Dan Ritter <dsr@randomstring.org> |
|---|---|
| Date | 2022-05-03 23:10 +0200 |
| Message-ID | <Ej7Wp-d0wI-19@gated-at.bofh.it> |
| In reply to | #247863 |
Tom Browder wrote: > I'm considering HaProxy downsteam from the router. > > That also brings the question, why do you need a static IPv4 address? If you want a service inside your network to be available to people outside your network (i.e. on the Internet), they need to be able to name it and get packets to it. The name is registered in the DNS (domain name service) and handled by DNS servers, either other people's for a fee or your own. If you have a static IPv4 address, you can assign many names to it via DNS CNAME records. If you have a static IPv6 address, you can assign many names to it via DNS, but only about half the people in the world will be able to get to it. If you don't have a static IPv4 address, but you can accept a few minutes of unreachability from time to time, you can use a dynamic DNS service and a daemon running on one of your machines that will contact it periodically to let the service know what's changed. -dsr-
[toc] | [prev] | [next] | [standalone]
| From | john doe <johndoe65534@mail.com> |
|---|---|
| Date | 2022-05-04 18:10 +0200 |
| Message-ID | <EjpJD-dciS-1@gated-at.bofh.it> |
| In reply to | #247863 |
On 5/3/2022 10:35 PM, Tom Browder wrote: > On Tue, May 3, 2022 at 15:18 john doe <johndoe65534@mail.com> wrote: > >> On 5/3/2022 9:42 PM, Tom Browder wrote: >>> I'm about to sign up for a fixed IPv4 address to my home. I know a bit >>> about setting up simple internal networks, but want to make sure I'm >>> doing it all correctly and securely. Does anyone have a good book they >>> recommend for such use? >>> >> >> What do you mean by "correctly and securly", the networking is never >> secure. > > > Thanks, I didn't know that. > > Depending on what you need, you might want firewall ... > > > I'm considering HaProxy downsteam from the router. > > That also brings the question, why do you need a static IPv4 address? > > > I'm moving my webservers inside. > I've learned my networking knowlage by reading on line or asking questions when I'm stuck! :) So I can not recommend a book. Here are some comments in addition to this thread: - Do not use the router capability provided by your ISP. This is mainly to avoid letting your ISP remotely control the thing and disable the firewall for example. If you can, use your own router. If your ISP requires to work with their router put the ISP thing in 'bridge'/modem only mode, this will allow to get your public IPv4 address to your own gateway. - Use VPN to access your servers remotely. I find it easier to use a VPN (responsible for public remote connection) to connect to my own network then use SSH (responsible for private remote connection) to connect to my intranet devices This also give you two layers of authentication and you have separate services. -- John Doe
[toc] | [prev] | [next] | [standalone]
| From | Tom Browder <tom.browder@gmail.com> |
|---|---|
| Date | 2022-05-05 16:40 +0200 |
| Message-ID | <EjKO8-dpRr-29@gated-at.bofh.it> |
| In reply to | #247900 |
[Multipart message — attachments visible in raw view] — view raw
On Wed, May 4, 2022 at 11:07 john doe <johndoe65534@mail.com> wrote:
> > On Tue, May 3, 2022 at 15:18 john doe <johndoe65534@mail.com> wrote:
> >> On 5/3/2022 9:42 PM, Tom Browder wrote:
>>> I'm about to sign up for a fixed IPv4 address to my home. I know a bit
> >>> about setting up simple internal networks, but want to make sure I'm
>>> doing it all correctly and securely. Does anyone have a good book they
> >>> recommend for such use?
I found the book I once consulted and just bought the Kindle version:
Networking for Systems Administrators, Michael W. Lucas, 2014
Mr. Lucas has also written books on *BSD, ssh, and DNS.
Here are some comments in addition to this thread:
> - Do not use the router capability provided by your ISP.
> This is mainly to avoid letting your ISP remotely control the thing and
> disable the firewall for example.
Good advice.
If you can, use your own router.
Ditto.
If your ISP requires to work with their router put the ISP thing in
> 'bridge'/modem only mode, this will allow to get your public IPv4
> address to your own gateway.
Check.
- Use VPN to access your servers remotely.
> I find it easier to use a VPN (responsible for public remote connection)
> to connect to my own network then use SSH (responsible for private
> remote connection) to connect to my intranet devices
>
> This also give you two layers of authentication and you have separate
> services.
But, given a properly passwordless ssh connection, is there anything
extraordinarily dangerous versus a VPN, or is it the redundancy you favor?
(I am the only superuser, and usually the only user of my network.)
BTW, regarding pfsense, I forgot it runs on BSD, so I plan to get their
small appliance to hang off the ISP router.
Thanks, Mr. John Doe.
-Tom
[toc] | [prev] | [next] | [standalone]
| From | john doe <johndoe65534@mail.com> |
|---|---|
| Date | 2022-05-05 21:40 +0200 |
| Message-ID | <EjPuq-dt3A-5@gated-at.bofh.it> |
| In reply to | #247920 |
On 5/5/2022 4:34 PM, Tom Browder wrote:
> On Wed, May 4, 2022 at 11:07 john doe <johndoe65534@mail.com> wrote:
>
>>> On Tue, May 3, 2022 at 15:18 john doe <johndoe65534@mail.com> wrote:
>>>> On 5/3/2022 9:42 PM, Tom Browder wrote:
>
> - Use VPN to access your servers remotely.
>
>
>> I find it easier to use a VPN (responsible for public remote connection)
>> to connect to my own network then use SSH (responsible for private
>> remote connection) to connect to my intranet devices
>>
>> This also give you two layers of authentication and you have separate
>> services.
>
>
> But, given a properly passwordless ssh connection, is there anything
> extraordinarily dangerous versus a VPN, or is it the redundancy you favor?
> (I am the only superuser, and usually the only user of my network.)
>
Yes, redundancy avoid having one point of failure in case of compromized
keys for example.
Having outbound connection through the VPN allows me to separate the
services, so if I need to work on the VPN I do not need to touch the SSH
server and vice versa
It also give me better firewalling capability between the VPN subnet and
the rest of my network.
For context, I'm also the only administrator ('root' user ...) on my
network.
See (1) and (2) for more in-depth thoughts.
At the time I set up this, I googled this subject and came to the
conclusion that SSH through VPN was a better fit (flexibility, two
layers of security, VPN advantages when connecting on public wifi) for me.
1)
https://networkengineering.stackexchange.com/questions/23959/why-use-ssh-and-vpn-in-combination
2) https://homenetworkguy.com/tech/ssh-vs-vpn/
--
John Doe
[toc] | [prev] | [next] | [standalone]
| From | David Christensen <dpchrist@holgerdanske.com> |
|---|---|
| Date | 2022-05-05 23:10 +0200 |
| Message-ID | <EjQTv-du3Q-5@gated-at.bofh.it> |
| In reply to | #247923 |
On 5/5/22 12:31, john doe wrote: > At the time I set up this, I googled this subject and came to the > conclusion that SSH through VPN was a better fit (flexibility, two > layers of security, VPN advantages when connecting on public wifi) for me. I prefer to have SSH available both via old-school port forwarding and via VPN. That way, when one breaks the other may still work. It's always a challenge trying to balance the convenience of centralization during normal operations against fall-back capabilities during adverse conditions. The latter can be thought of as a form of risk management. David
[toc] | [prev] | [next] | [standalone]
| From | Tom Browder <tom.browder@gmail.com> |
|---|---|
| Date | 2022-05-06 00:40 +0200 |
| Message-ID | <EjSiC-duSd-5@gated-at.bofh.it> |
| In reply to | #247925 |
[Multipart message — attachments visible in raw view] — view raw
On Thu, May 5, 2022 at 16:07 David Christensen <dpchrist@holgerdanske.com> wrote: > On 5/5/22 12:31, john doe wrote: > > > At the time I set up this, I googled this subject and came to the > > conclusion that SSH through VPN was a better fit (flexibility, two > > layers of security, VPN advantages when connecting on public wifi) for > me. The only experience with VPN I've had was when I was working from home back in 2010 running Debian on a company laptop and a kludge Cisco VPN program that somehow "just worked." If I go the pfsense/Netgate route (it has a VPN capability) what client do I use on my Debian hosts both internal and external? -Tom
[toc] | [prev] | [next] | [standalone]
| From | Celejar <celejar@gmail.com> |
|---|---|
| Date | 2022-05-06 03:50 +0200 |
| Message-ID | <EjVgu-dwOJ-1@gated-at.bofh.it> |
| In reply to | #247926 |
On Thu, 5 May 2022 17:36:14 -0500 Tom Browder <tom.browder@gmail.com> wrote: > On Thu, May 5, 2022 at 16:07 David Christensen <dpchrist@holgerdanske.com> > wrote: > > > On 5/5/22 12:31, john doe wrote: > > > > > At the time I set up this, I googled this subject and came to the > > > conclusion that SSH through VPN was a better fit (flexibility, two > > > layers of security, VPN advantages when connecting on public wifi) for > > me. > > > The only experience with VPN I've had was when I was working from home back > in 2010 running Debian on a company laptop and a kludge Cisco VPN program > that somehow "just worked." > > If I go the pfsense/Netgate route (it has a VPN capability) what client do > I use on my Debian hosts both internal and external? Depends on what VPN technology you're using. If you have no technical debt, Wireguard is definitely the way to go. On both ends, just install the Debian wireguard package (and its dependencies), edit the appropriate configuration files, and you're good to go. -- Celejar
[toc] | [prev] | [next] | [standalone]
| From | Dan Ritter <dsr@randomstring.org> |
|---|---|
| Date | 2022-05-06 04:00 +0200 |
| Message-ID | <EjVq9-dwRF-1@gated-at.bofh.it> |
| In reply to | #247926 |
Tom Browder wrote: > On Thu, May 5, 2022 at 16:07 David Christensen <dpchrist@holgerdanske.com> > wrote: > > > On 5/5/22 12:31, john doe wrote: > > > > > At the time I set up this, I googled this subject and came to the > > > conclusion that SSH through VPN was a better fit (flexibility, two > > > layers of security, VPN advantages when connecting on public wifi) for > > me. > > > The only experience with VPN I've had was when I was working from home back > in 2010 running Debian on a company laptop and a kludge Cisco VPN program > that somehow "just worked." > > If I go the pfsense/Netgate route (it has a VPN capability) what client do > I use on my Debian hosts both internal and external? Wireguard is now built in to the kernel (dkms module prior to bullseye). It is the easiest to configure, being slightly easier than SSH, and by far the fastest/most CPU efficient. sudo apt install wireguard-tools will get you the userland parts. -dsr-
[toc] | [prev] | [next] | [standalone]
| From | john doe <johndoe65534@mail.com> |
|---|---|
| Date | 2022-05-06 09:00 +0200 |
| Message-ID | <Ek06t-dzN0-3@gated-at.bofh.it> |
| In reply to | #247926 |
On 5/6/2022 12:36 AM, Tom Browder wrote: > On Thu, May 5, 2022 at 16:07 David Christensen <dpchrist@holgerdanske.com> > wrote: > >> On 5/5/22 12:31, john doe wrote: >> >>> At the time I set up this, I googled this subject and came to the >>> conclusion that SSH through VPN was a better fit (flexibility, two >>> layers of security, VPN advantages when connecting on public wifi) for >> me. > > > The only experience with VPN I've had was when I was working from home back > in 2010 running Debian on a company laptop and a kludge Cisco VPN program > that somehow "just worked." > > If I go the pfsense/Netgate route (it has a VPN capability) what client do > I use on my Debian hosts both internal and external? > According to (1), that could be OpenVPN. As I'm not using pfSense, I can only point you to the doc! :) 1) https://docs.netgate.com/pfsense/en/latest/recipes/openvpn-ra.html -- John Doe
[toc] | [prev] | [next] | [standalone]
| From | David Christensen <dpchrist@holgerdanske.com> |
|---|---|
| Date | 2022-05-05 22:50 +0200 |
| Message-ID | <EjQA9-dtG6-1@gated-at.bofh.it> |
| In reply to | #247920 |
On 5/4/22 09:07, john doe wrote:
> Here are some comments in addition to this thread:
> - Do not use the router capability provided by your ISP.
> This is mainly to avoid letting your ISP remotely control the thing and
> disable the firewall for example.
>
> If you can, use your own router.
>
> If your ISP requires to work with their router put the ISP thing in
> 'bridge'/modem only mode, this will allow to get your public IPv4
> address to your own gateway.
As per the OP, I also have AT&T residential service. I use a
router-behind-router configuration -- an AT&T residential gateway
between the Internet and what is effectively a DMZ, and a UniFi Security
Gateway 3P between the DMZ and the LAN. Advantages of this
configuration include:
1. The AT&T DMZ is available (wired and Wi-Fi) when the UniFi LAN is
down for maintenance or modification. My wife and children need
Internet connectivity 24x7, regardless of my "experiments".
2, I can connect a laptop to the DMZ and configure/ test/ verify/
trouble-shoot UniFi from the outside (notably laptop VPN connectivity).
On 5/5/22 07:34, Tom Browder wrote:
> ... given a properly passwordless ssh connection, is there anything
> extraordinarily dangerous versus a VPN, or is it the redundancy you
favor?
> (I am the only superuser, and usually the only user of my network.)
AIUI SSH with passwords disabled and strong passphrase-protected keys is
secure.
AIUI VPN with strong pre-shared keys and strong passphrases is secure.
My primary use-case for SSH is CVS. This can be accomplished via port
forwarding on the gateway. (The router-behind-router topology means I
need to do this twice.) The challenge is when you want to access
multiple LAN hosts via SSH. Options include adding (and translating)
non-standard ports, and using an SSH jump host. (Lucas recommends the
latter.)
A VPN connection means that my laptop can see all hosts and services on
the LAN when I am remote. My primary use-case is accessing the file
server (Samba) using a GUI file manager application. I can also SSH
directly into any host. UniFi provides the network tools for the VPN,
and Windows and macOS provide the client tools for the VPN. I have
never succeeded configuring a VPN client on Debian.
> BTW, regarding pfsense, I forgot it runs on BSD, so I plan to get their
> small appliance to hang off the ISP router.
Prior to UniFi, I variously used PC's with general-purpose (Red Hat,
Debian) and purpose-built Linux (IPCop) and BSD (pfSense) distributions,
and commercial routers (Netgear) with stock and FOSS (OpenWRT) firmware
as Internet gateways/ routers. Raw Linux was configured via the
console. All the others had web control panels. Then I added a Wi-Fi
access point. Now I needed to keep two device settings in sync via two
web control panels. It was tedious. Then I added a remote site,
dynamic DNS, and connected the two sites with a VPN. Management became
a PITA.
I currently have one site with one UniFi security gateway (USG) and
three UniFi Wi-Fi access points. Management is via one UniFi web
control panel running on a purpose-built VPS. The UniFi controller
manages and synchronizes the settings on individual devices based upon
higher level abstractions ("Software Defined Networking"), such as
networks. I defined a network, followed the protocol to adopt hardware
devices, and it just works. Management is easy. UniFi provides many
additional features, including port-forwarding and VPN's.
Note that UniFi hardware products run embedded Linux. When I encounter
a difficult trouble-shooting problem, UniFi technical support guided me
to a console roll-up cable for the USG, and helped me configure system
logging to a network host.
David
[toc] | [prev] | [next] | [standalone]
| From | Charles Curley <charlescurley@charlescurley.com> |
|---|---|
| Date | 2022-05-03 22:40 +0200 |
| Message-ID | <Ej7tn-d07E-3@gated-at.bofh.it> |
| In reply to | #247859 |
On Tue, 3 May 2022 14:42:16 -0500 Tom Browder <tom.browder@gmail.com> wrote: > I'm about to sign up for a fixed IPv4 address to my home. I know a bit > about setting up simple internal networks, but want to make sure I'm > doing it all correctly and securely. Does anyone have a good book they > recommend for such use? You said, "a fixed IPv4 address", which suggests you'll be doing NATting (or whatever they call it this week) for your home network. I use Æleen Frisch, Essential System Administration, 2nd ed. https://www.oreilly.com/library/view/essential-system-administration/0596003439/ I see the current edition is 3rd, dated 2002. So possibly dated, but the basics will be the same. No systemd, though. You will want to get up to speed on firewalling, if you aren't already. Allow your systems to connect to any external server. Don't allow any external access to anything on your firewall or home network unless it's for a service you provide to the outside world. You will want to parcel out IP addresses and host names on your home network, so DNS and DHCP. There are other programs to do those things, but bind and dhcpd are classics, and talk to each other. Wireless is nice, but a security nightmare. And don't forget to do backups. -- Does anybody read signatures any more? https://charlescurley.com https://charlescurley.com/blog/
[toc] | [prev] | [next] | [standalone]
| From | Tixy <tixy@yxit.co.uk> |
|---|---|
| Date | 2022-05-03 23:00 +0200 |
| Message-ID | <Ej7MJ-d0dU-3@gated-at.bofh.it> |
| In reply to | #247864 |
On Tue, 2022-05-03 at 14:30 -0600, Charles Curley wrote: > [...] > You will want to parcel out IP addresses and host names on your home > network, so DNS and DHCP. There are other programs to do those things, > but bind and dhcpd are classics, and talk to each other. Or dnsmasq which does both jobs, so just one program and one config file to deal with. -- Tixy
[toc] | [prev] | [next] | [standalone]
| From | Dan Ritter <dsr@randomstring.org> |
|---|---|
| Date | 2022-05-03 23:00 +0200 |
| Message-ID | <Ej7MJ-d0dU-1@gated-at.bofh.it> |
| In reply to | #247859 |
Tom Browder wrote: > I'm about to sign up for a fixed IPv4 address to my home. I know a bit > about setting up simple internal networks, but want to make sure I'm > doing it all correctly and securely. Does anyone have a good book they > recommend for such use? Almost certainly what you want is Concepts (old but useful): https://www.nftables.org/documentation/HOWTO/packet-filtering-HOWTO.html What to do: https://wiki.nftables.org/wiki-nftables/index.php/Simple_ruleset_for_a_home_router How to do it in Debian: https://www.debian.org/doc/manuals/debian-handbook/sect.firewall-packet-filtering.en.html Reference: https://netfilter.org/ And the invaluable: https://stuffphilwrites.com/2014/09/iptables-processing-flowchart/ -dsr-
[toc] | [prev] | [next] | [standalone]
| From | Tom Browder <tom.browder@gmail.com> |
|---|---|
| Date | 2022-05-03 23:20 +0200 |
| Message-ID | <Ej865-d0A5-9@gated-at.bofh.it> |
| In reply to | #247859 |
[Multipart message — attachments visible in raw view] — view raw
On Tue, May 3, 2022 at 14:42 Tom Browder <tom.browder@gmail.com> wrote: > I'm about to sign up for a fixed IPv4 address to my home. I know a bit > about setting up simple internal networks, but want to make sure I'm > doing it all correctly and securely. Does anyone have a good book they > recommend for such use? I appreciate all the responses, and I realize, once again, that I should have given a little more background for the question: I have been running 10+ websites using SNI on Apache on two leased remote servers for many years. I am now moving the whole operation, gradually, to operate out of my home on my own Debian server. During those years I've had several hardware failures that were hard to deal with remotely, hence the decision to come home (especially since I now have a bit more space for the additional equipment). I have been using a firewall and iptables to minimize inbound traffic, but the details some have sent are very helpful for my current plan. In addition to the webserver being accessed externally, I will be sshing into my home server while traveling. Thanks to all. -Tom
[toc] | [prev] | [next] | [standalone]
Page 1 of 2 [1] 2 Next page →
Back to top | Article view | linux.debian.user
csiph-web