Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #247859 > unrolled thread

Networking book recommendation

Started byTom Browder <tom.browder@gmail.com>
First post2022-05-03 21:50 +0200
Last post2022-05-07 10:00 +0200
Articles 20 on this page of 26 — 12 participants

Back to article view | Back to linux.debian.user


Contents

  Networking book recommendation Tom Browder <tom.browder@gmail.com> - 2022-05-03 21:50 +0200
    Re: Networking book recommendation john doe <johndoe65534@mail.com> - 2022-05-03 22:20 +0200
      Re: Networking book recommendation Jeremy Ardley <jeremy@ardley.org> - 2022-05-03 22:30 +0200
        Re: Networking book recommendation <tomas@tuxteam.de> - 2022-05-04 07:00 +0200
          Re: Networking book recommendation Jeremy Ardley <jeremy@ardley.org> - 2022-05-04 08:00 +0200
      Re: Networking book recommendation Tom Browder <tom.browder@gmail.com> - 2022-05-03 22:40 +0200
        Re: Networking book recommendation Dan Ritter <dsr@randomstring.org> - 2022-05-03 23:10 +0200
        Re: Networking book recommendation john doe <johndoe65534@mail.com> - 2022-05-04 18:10 +0200
          Re: Networking book recommendation Tom Browder <tom.browder@gmail.com> - 2022-05-05 16:40 +0200
            Re: Networking book recommendation john doe <johndoe65534@mail.com> - 2022-05-05 21:40 +0200
              Re: Networking book recommendation David Christensen <dpchrist@holgerdanske.com> - 2022-05-05 23:10 +0200
                Re: Networking book recommendation Tom Browder <tom.browder@gmail.com> - 2022-05-06 00:40 +0200
                  Re: Networking book recommendation Celejar <celejar@gmail.com> - 2022-05-06 03:50 +0200
                  Re: Networking book recommendation Dan Ritter <dsr@randomstring.org> - 2022-05-06 04:00 +0200
                  Re: Networking book recommendation john doe <johndoe65534@mail.com> - 2022-05-06 09:00 +0200
            Re: Networking book recommendation David Christensen <dpchrist@holgerdanske.com> - 2022-05-05 22:50 +0200
    Re: Networking book recommendation Charles Curley <charlescurley@charlescurley.com> - 2022-05-03 22:40 +0200
      Re: Networking book recommendation Tixy <tixy@yxit.co.uk> - 2022-05-03 23:00 +0200
    Re: Networking book recommendation Dan Ritter <dsr@randomstring.org> - 2022-05-03 23:00 +0200
    Re: Networking book recommendation Tom Browder <tom.browder@gmail.com> - 2022-05-03 23:20 +0200
      Re: Networking book recommendation Greg Wooledge <greg@wooledge.org> - 2022-05-03 23:30 +0200
        Re: Networking book recommendation Tom Browder <tom.browder@gmail.com> - 2022-05-03 23:40 +0200
      Re: Networking book recommendation Bob Weber <bobrweber@gmail.com> - 2022-05-04 00:30 +0200
        Re: Networking book recommendation Tom Browder <tom.browder@gmail.com> - 2022-05-04 01:40 +0200
    Re: Networking book recommendation David Christensen <dpchrist@holgerdanske.com> - 2022-05-04 01:50 +0200
    Re: Networking book recommendation "Rick Thomas" <rick.thomas@pobox.com> - 2022-05-07 10:00 +0200

Page 1 of 2  [1] 2  Next page →


#247859 — Networking book recommendation

FromTom Browder <tom.browder@gmail.com>
Date2022-05-03 21:50 +0200
SubjectNetworking book recommendation
Message-ID<Ej6GZ-cZwJ-3@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

I'm about to sign up for a fixed IPv4 address to my home. I know a bit
about setting up simple internal networks, but want to make sure I'm
doing it all correctly and securely. Does anyone have a good book they
recommend for such use?

Thanks.

-Tom

[toc] | [next] | [standalone]


#247861

Fromjohn doe <johndoe65534@mail.com>
Date2022-05-03 22:20 +0200
Message-ID<Ej7a1-d01z-1@gated-at.bofh.it>
In reply to#247859
On 5/3/2022 9:42 PM, Tom Browder wrote:
> I'm about to sign up for a fixed IPv4 address to my home. I know a bit
> about setting up simple internal networks, but want to make sure I'm
> doing it all correctly and securely. Does anyone have a good book they
> recommend for such use?
>

What do you mean by "correctly and securly", the networking is never secure.
Depending on what you need, you might want firewall ...

That also brings the question, why do you need a static IPv4 address?

--
John Doe

[toc] | [prev] | [next] | [standalone]


#247862

FromJeremy Ardley <jeremy@ardley.org>
Date2022-05-03 22:30 +0200
Message-ID<Ej7jH-d04N-5@gated-at.bofh.it>
In reply to#247861

[Multipart message — attachments visible in raw view] — view raw

On 4/5/22 4:18 am, john doe wrote:
>
> What do you mean by "correctly and securly", the networking is never 
> secure.
> Depending on what you need, you might want firewall ...
>
> That also brings the question, why do you need a static IPv4 address?
>
>
For almost all domestic installations a single static IPv4 address is 
managed by the router and used to NAT internal addresses. NAT in itself 
provides quite good security because internal hosts can't be scanned by 
attackers.

If the router is a normal commercial router it will manage the internal 
network and will itself have very few vulnerabilities

If the static IPv4 address is to be used to provide a public service 
then it's usual to forward inbound connections to an internal host to 
provide that service. That forwarding is usually router specific.


-- 
Jeremy

[toc] | [prev] | [next] | [standalone]


#247884

From<tomas@tuxteam.de>
Date2022-05-04 07:00 +0200
Message-ID<Ejfhf-d5eH-1@gated-at.bofh.it>
In reply to#247862

[Multipart message — attachments visible in raw view] — view raw

On Wed, May 04, 2022 at 04:27:52AM +0800, Jeremy Ardley wrote:

[...]

> [...] NAT in itself
> provides quite good security because internal hosts can't be scanned by
> attackers.

Uh, oh. I think general opinion these days disagree with this
statement strongly (see e.g. [1], but this has been rough
consensus since at least the 2000s).

That said, even "normal" hands-off firewalls don't help against
the most widespread threats of these days: malicious actors that
are located inside your network: be it some random javascript
running in your browser, a printer phoning home or your so-called
smart TV.

All of those will connect to outside things from the inside, and
a no-trouble hands-off firewall is configured to allow just that.

The known attacks against NAT dwindle given the above-mentioned
cornucopia :-)

Don't get me started on things like UPMP's NAT-PMP [2] which are
explicitily designed for clients to punch holes into the firewall.

Cheers

[1] https://security.stackexchange.com/questions/8772/how-important-is-nat-as-a-security-layer
[2] https://en.wikipedia.org/wiki/NAT_Port_Mapping_Protocol
-- 
t

[toc] | [prev] | [next] | [standalone]


#247886

FromJeremy Ardley <jeremy@ardley.org>
Date2022-05-04 08:00 +0200
Message-ID<Ejgdj-d5U6-5@gated-at.bofh.it>
In reply to#247884

[Multipart message — attachments visible in raw view] — view raw

On 4/5/22 12:57 pm, tomas@tuxteam.de wrote:
> On Wed, May 04, 2022 at 04:27:52AM +0800, Jeremy Ardley wrote:
>
> [...]
>
>> [...] NAT in itself
>> provides quite good security because internal hosts can't be scanned by
>> attackers.
> Uh, oh. I think general opinion these days disagree with this
> statement strongly (see e.g. [1], but this has been rough
> consensus since at least the 2000s).

Your consensus is 20 years old. Times move

Natural evolution has developed standard features in routers that out of 
the box are 'good enough' for SOHO implementations.

That is when you plug it in and connect to your home LAN you can 
reasonably expect your LAN won't be compromised in 5 minutes or even 5 
years of persistent attacks.

The only problem is when the enthusiastic owner starts opening ports to 
allow internal mail or web, or even just to run some games. This problem 
will also occur when you have the latest fancy dandy firewall. It is 
users who are insecure, not NAT or routers as such.

More interesting is IPv6 which many ISPs now offer. Modern routers know 
about Prefix delegation and all your windows hosts will automatically 
pick up IPv6 Addresses. These are 'raw' on the internet, no NAT 
involved. It will depend on your router firewall on how well protected 
you are.

In the IPv6 case, modern Windows machines all have inbuilt firewalls 
that work reasonably well. Linux systems are variable in firewall 
configuration and may not be as well protected.

I run my own Armbian dual homed router that does the IPv6 stuff and I 
have a reasonable set of ip6tables rules to allow specific hosts to 
provide IPv6 services on well known addresses (ie in DNS) but at the 
same time protect most other hosts from any unsolicited IPv6 Traffic.

If I was still in the 90s I'd set up a DMZ blah blah. Now I just expose 
services on the router using HA proxy for IPv4 Stuff and specific rules 
for IPv6. I also run a postfix instance on the router for IPv4 connectivity.


Jeremy

[toc] | [prev] | [next] | [standalone]


#247863

FromTom Browder <tom.browder@gmail.com>
Date2022-05-03 22:40 +0200
Message-ID<Ej7tn-d07E-1@gated-at.bofh.it>
In reply to#247861

[Multipart message — attachments visible in raw view] — view raw

On Tue, May 3, 2022 at 15:18 john doe <johndoe65534@mail.com> wrote:

> On 5/3/2022 9:42 PM, Tom Browder wrote:
> > I'm about to sign up for a fixed IPv4 address to my home. I know a bit
> > about setting up simple internal networks, but want to make sure I'm
> > doing it all correctly and securely. Does anyone have a good book they
> > recommend for such use?
> >
>
> What do you mean by "correctly and securly", the networking is never
> secure.


Thanks, I didn't know that.

Depending on what you need, you might want firewall ...


I'm considering HaProxy downsteam from the router.

That also brings the question, why do you need a static IPv4 address?


I'm moving my webservers inside.

Thanks.

-Tom

[toc] | [prev] | [next] | [standalone]


#247867

FromDan Ritter <dsr@randomstring.org>
Date2022-05-03 23:10 +0200
Message-ID<Ej7Wp-d0wI-19@gated-at.bofh.it>
In reply to#247863
Tom Browder wrote: 
> I'm considering HaProxy downsteam from the router.
> 
> That also brings the question, why do you need a static IPv4 address?

If you want a service inside your network to be available to
people outside your network (i.e. on the Internet), they need to
be able to name it and get packets to it.

The name is registered in the DNS (domain name service) and
handled by DNS servers, either other people's for a fee or
your own.

If you have a static IPv4 address, you can assign many names to
it via DNS CNAME records.

If you have a static IPv6 address, you can assign many names to
it via DNS, but only about half the people in the world will be
able to get to it.

If you don't have a static IPv4 address, but you can accept a
few minutes of unreachability from time to time, you can use a
dynamic DNS service and a daemon running on one of your machines
that will contact it periodically to let the service know what's
changed.

-dsr-

[toc] | [prev] | [next] | [standalone]


#247900

Fromjohn doe <johndoe65534@mail.com>
Date2022-05-04 18:10 +0200
Message-ID<EjpJD-dciS-1@gated-at.bofh.it>
In reply to#247863
On 5/3/2022 10:35 PM, Tom Browder wrote:
> On Tue, May 3, 2022 at 15:18 john doe <johndoe65534@mail.com> wrote:
>
>> On 5/3/2022 9:42 PM, Tom Browder wrote:
>>> I'm about to sign up for a fixed IPv4 address to my home. I know a bit
>>> about setting up simple internal networks, but want to make sure I'm
>>> doing it all correctly and securely. Does anyone have a good book they
>>> recommend for such use?
>>>
>>
>> What do you mean by "correctly and securly", the networking is never
>> secure.
>
>
> Thanks, I didn't know that.
>
> Depending on what you need, you might want firewall ...
>
>
> I'm considering HaProxy downsteam from the router.
>
> That also brings the question, why do you need a static IPv4 address?
>
>
> I'm moving my webservers inside.
>

I've learned my networking knowlage by reading on line or asking
questions when I'm stuck! :)

So I can not recommend a book.

Here are some comments in addition to this thread:
- Do not use the router capability provided by your ISP.
This is mainly to avoid letting your ISP remotely control the thing and
disable the firewall for example.

If you can, use your own router.

If your ISP requires to work with their router put the ISP thing in
'bridge'/modem only mode, this will allow to get your public IPv4
address to your own gateway.


- Use VPN to access your servers remotely.

I find it easier to use a VPN (responsible for public remote connection)
to connect to my own network then use SSH (responsible for private
remote connection) to connect to my intranet devices

This also give you two layers of authentication and you have separate
services.

--
John Doe

[toc] | [prev] | [next] | [standalone]


#247920

FromTom Browder <tom.browder@gmail.com>
Date2022-05-05 16:40 +0200
Message-ID<EjKO8-dpRr-29@gated-at.bofh.it>
In reply to#247900

[Multipart message — attachments visible in raw view] — view raw

On Wed, May 4, 2022 at 11:07 john doe <johndoe65534@mail.com> wrote:

> > On Tue, May 3, 2022 at 15:18 john doe <johndoe65534@mail.com> wrote:
> >> On 5/3/2022 9:42 PM, Tom Browder wrote:

  >>> I'm about to sign up for a fixed IPv4 address to my home. I know a bit

> >>> about setting up simple internal networks, but want to make sure I'm

>>> doing it all correctly and securely. Does anyone have a good book they
> >>> recommend for such use?


I found the book I once consulted and just bought the Kindle version:

    Networking for Systems Administrators, Michael W. Lucas, 2014

Mr. Lucas has also written books on *BSD, ssh, and DNS.

Here are some comments in addition to this thread:
> - Do not use the router capability provided by your ISP.
> This is mainly to avoid letting your ISP remotely control the thing and
> disable the firewall for example.


Good advice.

If you can, use your own router.


Ditto.

If your ISP requires to work with their router put the ISP thing in
> 'bridge'/modem only mode, this will allow to get your public IPv4
> address to your own gateway.


Check.

- Use VPN to access your servers remotely.


> I find it easier to use a VPN (responsible for public remote connection)
> to connect to my own network then use SSH (responsible for private
> remote connection) to connect to my intranet devices
>
> This also give you two layers of authentication and you have separate
> services.


But, given a properly passwordless ssh connection, is there anything
extraordinarily dangerous versus a VPN, or is it the redundancy you favor?
(I am the only superuser, and usually the only user of my network.)

BTW, regarding pfsense, I forgot it runs on BSD, so I plan to get their
small appliance to hang off the ISP router.

Thanks, Mr. John Doe.

-Tom

[toc] | [prev] | [next] | [standalone]


#247923

Fromjohn doe <johndoe65534@mail.com>
Date2022-05-05 21:40 +0200
Message-ID<EjPuq-dt3A-5@gated-at.bofh.it>
In reply to#247920
On 5/5/2022 4:34 PM, Tom Browder wrote:
> On Wed, May 4, 2022 at 11:07 john doe <johndoe65534@mail.com> wrote:
>
>>> On Tue, May 3, 2022 at 15:18 john doe <johndoe65534@mail.com> wrote:
>>>> On 5/3/2022 9:42 PM, Tom Browder wrote:
>
> - Use VPN to access your servers remotely.
>
>
>> I find it easier to use a VPN (responsible for public remote connection)
>> to connect to my own network then use SSH (responsible for private
>> remote connection) to connect to my intranet devices
>>
>> This also give you two layers of authentication and you have separate
>> services.
>
>
> But, given a properly passwordless ssh connection, is there anything
> extraordinarily dangerous versus a VPN, or is it the redundancy you favor?
> (I am the only superuser, and usually the only user of my network.)
>

Yes, redundancy avoid having one point of failure in case of compromized
keys for example.

Having outbound connection through the VPN allows me to separate the
services, so if I need to work on the VPN I do not need to touch the SSH
server and vice versa
It also give me better firewalling capability between the VPN subnet and
the rest of my network.


For context, I'm also the only administrator ('root' user ...) on my
network.


See (1) and (2) for more in-depth thoughts.
At the time I set up this, I googled this subject and came to the
conclusion that SSH through VPN was a better fit (flexibility, two
layers of security, VPN advantages when connecting on public wifi) for me.


1)
https://networkengineering.stackexchange.com/questions/23959/why-use-ssh-and-vpn-in-combination
2)  https://homenetworkguy.com/tech/ssh-vs-vpn/

--
John Doe

[toc] | [prev] | [next] | [standalone]


#247925

FromDavid Christensen <dpchrist@holgerdanske.com>
Date2022-05-05 23:10 +0200
Message-ID<EjQTv-du3Q-5@gated-at.bofh.it>
In reply to#247923
On 5/5/22 12:31, john doe wrote:

> At the time I set up this, I googled this subject and came to the
> conclusion that SSH through VPN was a better fit (flexibility, two
> layers of security, VPN advantages when connecting on public wifi) for me.


I prefer to have SSH available both via old-school port forwarding and 
via VPN.  That way, when one breaks the other may still work.


It's always a challenge trying to balance the convenience of 
centralization during normal operations against fall-back capabilities 
during adverse conditions.  The latter can be thought of as a form of 
risk management.


David

[toc] | [prev] | [next] | [standalone]


#247926

FromTom Browder <tom.browder@gmail.com>
Date2022-05-06 00:40 +0200
Message-ID<EjSiC-duSd-5@gated-at.bofh.it>
In reply to#247925

[Multipart message — attachments visible in raw view] — view raw

On Thu, May 5, 2022 at 16:07 David Christensen <dpchrist@holgerdanske.com>
wrote:

> On 5/5/22 12:31, john doe wrote:
>
> > At the time I set up this, I googled this subject and came to the
> > conclusion that SSH through VPN was a better fit (flexibility, two
> > layers of security, VPN advantages when connecting on public wifi) for
> me.


The only experience with VPN I've had was when I was working from home back
in 2010 running Debian on a company laptop and a kludge Cisco VPN program
that somehow "just worked."

If I go the pfsense/Netgate route (it has a VPN capability) what client do
I use on my Debian hosts both internal and external?

-Tom

[toc] | [prev] | [next] | [standalone]


#247931

FromCelejar <celejar@gmail.com>
Date2022-05-06 03:50 +0200
Message-ID<EjVgu-dwOJ-1@gated-at.bofh.it>
In reply to#247926
On Thu, 5 May 2022 17:36:14 -0500
Tom Browder <tom.browder@gmail.com> wrote:

> On Thu, May 5, 2022 at 16:07 David Christensen <dpchrist@holgerdanske.com>
> wrote:
> 
> > On 5/5/22 12:31, john doe wrote:
> >
> > > At the time I set up this, I googled this subject and came to the
> > > conclusion that SSH through VPN was a better fit (flexibility, two
> > > layers of security, VPN advantages when connecting on public wifi) for
> > me.
> 
> 
> The only experience with VPN I've had was when I was working from home back
> in 2010 running Debian on a company laptop and a kludge Cisco VPN program
> that somehow "just worked."
> 
> If I go the pfsense/Netgate route (it has a VPN capability) what client do
> I use on my Debian hosts both internal and external?

Depends on what VPN technology you're using. If you have no technical
debt, Wireguard is definitely the way to go. On both ends, just install
the Debian wireguard package (and its dependencies), edit the
appropriate configuration files, and you're good to go.

-- 
Celejar

[toc] | [prev] | [next] | [standalone]


#247932

FromDan Ritter <dsr@randomstring.org>
Date2022-05-06 04:00 +0200
Message-ID<EjVq9-dwRF-1@gated-at.bofh.it>
In reply to#247926
Tom Browder wrote: 
> On Thu, May 5, 2022 at 16:07 David Christensen <dpchrist@holgerdanske.com>
> wrote:
> 
> > On 5/5/22 12:31, john doe wrote:
> >
> > > At the time I set up this, I googled this subject and came to the
> > > conclusion that SSH through VPN was a better fit (flexibility, two
> > > layers of security, VPN advantages when connecting on public wifi) for
> > me.
> 
> 
> The only experience with VPN I've had was when I was working from home back
> in 2010 running Debian on a company laptop and a kludge Cisco VPN program
> that somehow "just worked."
> 
> If I go the pfsense/Netgate route (it has a VPN capability) what client do
> I use on my Debian hosts both internal and external?

Wireguard is now built in to the kernel (dkms module prior to
bullseye). It is the easiest to configure, being slightly easier
than SSH, and by far the fastest/most CPU efficient.

sudo apt install wireguard-tools

will get you the userland parts.

-dsr-

[toc] | [prev] | [next] | [standalone]


#247933

Fromjohn doe <johndoe65534@mail.com>
Date2022-05-06 09:00 +0200
Message-ID<Ek06t-dzN0-3@gated-at.bofh.it>
In reply to#247926
On 5/6/2022 12:36 AM, Tom Browder wrote:
> On Thu, May 5, 2022 at 16:07 David Christensen <dpchrist@holgerdanske.com>
> wrote:
>
>> On 5/5/22 12:31, john doe wrote:
>>
>>> At the time I set up this, I googled this subject and came to the
>>> conclusion that SSH through VPN was a better fit (flexibility, two
>>> layers of security, VPN advantages when connecting on public wifi) for
>> me.
>
>
> The only experience with VPN I've had was when I was working from home back
> in 2010 running Debian on a company laptop and a kludge Cisco VPN program
> that somehow "just worked."
>
> If I go the pfsense/Netgate route (it has a VPN capability) what client do
> I use on my Debian hosts both internal and external?
>

According to (1), that could be OpenVPN.

As I'm not using pfSense, I can only point you to the doc! :)

1)  https://docs.netgate.com/pfsense/en/latest/recipes/openvpn-ra.html

--
John Doe

[toc] | [prev] | [next] | [standalone]


#247924

FromDavid Christensen <dpchrist@holgerdanske.com>
Date2022-05-05 22:50 +0200
Message-ID<EjQA9-dtG6-1@gated-at.bofh.it>
In reply to#247920
On 5/4/22 09:07, john doe wrote:
 > Here are some comments in addition to this thread:
 > - Do not use the router capability provided by your ISP.
 > This is mainly to avoid letting your ISP remotely control the thing and
 > disable the firewall for example.
 >
 > If you can, use your own router.
 >
 > If your ISP requires to work with their router put the ISP thing in
 > 'bridge'/modem only mode, this will allow to get your public IPv4
 > address to your own gateway.


As per the OP, I also have AT&T residential service.  I use a 
router-behind-router configuration -- an AT&T residential gateway 
between the Internet and what is effectively a DMZ, and a UniFi Security 
Gateway 3P between the DMZ and the LAN.  Advantages of this 
configuration include:

1.  The AT&T DMZ is available (wired and Wi-Fi) when the UniFi LAN is 
down for maintenance or modification.  My wife and children need 
Internet connectivity 24x7, regardless of my "experiments".

2,  I can connect a laptop to the DMZ and configure/ test/ verify/ 
trouble-shoot UniFi from the outside (notably laptop VPN connectivity).


On 5/5/22 07:34, Tom Browder wrote:

 > ... given a properly passwordless ssh connection, is there anything
 > extraordinarily dangerous versus a VPN, or is it the redundancy you 
favor?
 > (I am the only superuser, and usually the only user of my network.)


AIUI SSH with passwords disabled and strong passphrase-protected keys is 
secure.


AIUI VPN with strong pre-shared keys and strong passphrases is secure.


My primary use-case for SSH is CVS.  This can be accomplished via port 
forwarding on the gateway.  (The router-behind-router topology means I 
need to do this twice.)  The challenge is when you want to access 
multiple LAN hosts via SSH.  Options include adding (and translating) 
non-standard ports, and using an SSH jump host.  (Lucas recommends the 
latter.)


A VPN connection means that my laptop can see all hosts and services on 
the LAN when I am remote.  My primary use-case is accessing the file 
server (Samba) using a GUI file manager application.  I can also SSH 
directly into any host.  UniFi provides the network tools for the VPN, 
and Windows and macOS provide the client tools for the VPN.  I have 
never succeeded configuring a VPN client on Debian.


 > BTW, regarding pfsense, I forgot it runs on BSD, so I plan to get their
 > small appliance to hang off the ISP router.


Prior to UniFi, I variously used PC's with general-purpose (Red Hat, 
Debian) and purpose-built Linux (IPCop) and BSD (pfSense) distributions, 
and commercial routers (Netgear) with stock and FOSS (OpenWRT) firmware 
as Internet gateways/ routers.  Raw Linux was configured via the 
console.  All the others had web control panels.  Then I added a Wi-Fi 
access point.  Now I needed to keep two device settings in sync via two 
web control panels.  It was tedious.  Then I added a remote site, 
dynamic DNS, and connected the two sites with a VPN.  Management became 
a PITA.


I currently have one site with one UniFi security gateway (USG) and 
three UniFi Wi-Fi access points.  Management is via one UniFi web 
control panel running on a purpose-built VPS.  The UniFi controller 
manages and synchronizes the settings on individual devices based upon 
higher level abstractions ("Software Defined Networking"), such as 
networks.  I defined a network, followed the protocol to adopt hardware 
devices, and it just works.  Management is easy.  UniFi provides many 
additional features, including port-forwarding and VPN's.


Note that UniFi hardware products run embedded Linux.  When I encounter 
a difficult trouble-shooting problem, UniFi technical support guided me 
to a console roll-up cable for the USG, and helped me configure system 
logging to a network host.


David

[toc] | [prev] | [next] | [standalone]


#247864

FromCharles Curley <charlescurley@charlescurley.com>
Date2022-05-03 22:40 +0200
Message-ID<Ej7tn-d07E-3@gated-at.bofh.it>
In reply to#247859
On Tue, 3 May 2022 14:42:16 -0500
Tom Browder <tom.browder@gmail.com> wrote:

> I'm about to sign up for a fixed IPv4 address to my home. I know a bit
> about setting up simple internal networks, but want to make sure I'm
> doing it all correctly and securely. Does anyone have a good book they
> recommend for such use?

You said, "a fixed IPv4 address", which suggests you'll be doing
NATting (or whatever they call it this week) for your home network.

I use Æleen Frisch, Essential System Administration, 2nd ed.
https://www.oreilly.com/library/view/essential-system-administration/0596003439/
I see the current edition is 3rd, dated 2002. So possibly dated, but
the basics will be the same. No systemd, though.

You will want to get up to speed on firewalling, if you aren't already.
Allow your systems to connect to any external server. Don't allow any
external access to anything on your firewall or home network unless
it's for a service you provide to the outside world.

You will want to parcel out IP addresses and host names on your home
network, so DNS and DHCP. There are other programs to do those things,
but bind and dhcpd are classics, and talk to each other.

Wireless is nice, but a security nightmare.

And don't forget to do backups.

-- 
Does anybody read signatures any more?

https://charlescurley.com
https://charlescurley.com/blog/

[toc] | [prev] | [next] | [standalone]


#247865

FromTixy <tixy@yxit.co.uk>
Date2022-05-03 23:00 +0200
Message-ID<Ej7MJ-d0dU-3@gated-at.bofh.it>
In reply to#247864
On Tue, 2022-05-03 at 14:30 -0600, Charles Curley wrote:
> [...]
> You will want to parcel out IP addresses and host names on your home
> network, so DNS and DHCP. There are other programs to do those things,
> but bind and dhcpd are classics, and talk to each other.

Or dnsmasq which does both jobs, so just one program and one config
file to deal with.

-- 
Tixy

[toc] | [prev] | [next] | [standalone]


#247866

FromDan Ritter <dsr@randomstring.org>
Date2022-05-03 23:00 +0200
Message-ID<Ej7MJ-d0dU-1@gated-at.bofh.it>
In reply to#247859
Tom Browder wrote: 
> I'm about to sign up for a fixed IPv4 address to my home. I know a bit
> about setting up simple internal networks, but want to make sure I'm
> doing it all correctly and securely. Does anyone have a good book they
> recommend for such use?


Almost certainly what you want is 

Concepts (old but useful):
	https://www.nftables.org/documentation/HOWTO/packet-filtering-HOWTO.html

What to do:
	https://wiki.nftables.org/wiki-nftables/index.php/Simple_ruleset_for_a_home_router

How to do it in Debian:
	https://www.debian.org/doc/manuals/debian-handbook/sect.firewall-packet-filtering.en.html

Reference:
	https://netfilter.org/

And the invaluable:

	https://stuffphilwrites.com/2014/09/iptables-processing-flowchart/

-dsr-

[toc] | [prev] | [next] | [standalone]


#247868

FromTom Browder <tom.browder@gmail.com>
Date2022-05-03 23:20 +0200
Message-ID<Ej865-d0A5-9@gated-at.bofh.it>
In reply to#247859

[Multipart message — attachments visible in raw view] — view raw

On Tue, May 3, 2022 at 14:42 Tom Browder <tom.browder@gmail.com> wrote:

> I'm about to sign up for a fixed IPv4 address to my home. I know a bit
> about setting up simple internal networks, but want to make sure I'm
> doing it all correctly and securely. Does anyone have a good book they
> recommend for such use?


I appreciate all the responses, and I realize, once again, that I should
have given a little more background for the question:

I have been running 10+ websites using SNI on Apache on two leased remote
servers for many years. I am now moving the whole operation, gradually, to
operate out of my home on my own Debian server. During those years I've had
several hardware failures that were hard to deal with remotely, hence the
decision to come home (especially since I now have a bit more space for the
additional equipment).

I have been using a firewall and iptables to minimize inbound traffic, but
the details some have sent are very helpful for my current plan.

In addition to the webserver being accessed externally, I will be sshing
into my home server while traveling.

Thanks to all.

-Tom

[toc] | [prev] | [next] | [standalone]


Page 1 of 2  [1] 2  Next page →

Back to top | Article view | linux.debian.user


csiph-web