[TriLUG] 1 or 2 nics inside the lan?

bp bpevans at bellsouth.net
Fri Jan 10 11:12:29 EST 2003


I currently run my Red Hat 8 beta server behind a firewall appliance.  
The linux box has two nics.  One setup to use dhcp and provide smb 
services to the LAN.  The other nic was setup with a static ip and the 
router was given this ip as the dmz.  This was setup in a hurry and i'll 
be the first to admit it wasn't my finest work.  The dmz nic only 
listens to http/s, and ssh traffic.  The annoying part of this is that 
I'm out of ports on my switch, when I pull either cable from my server 
she dies because the routing table makes it act as 'in one nic, out the 
other'.  I realize I could probably tweak this with some smart route add 
cmds - but since I'm in the mood to reimage for a few reasons I thought 
I'd keep this question design oriented.

I'd like the list's impression about the security benefits of using two 
physical nics?  I'm thinking about pulling the second nic and setting 
the router up to only forward 22,80,443.  (Obviously safer than the 
current dmz config)  My original concern was that I didn't want any of 
my samba shares leaked outside my LAN which is why I bound it to the 
internal only nic of the current setup. 

I'm thinking of blowing everything away to install the stable version of 
rh8 soon, the current install was from a borrowed set of disk labeled 
"rh8 beta".  Is the psyche build fairly stable?  Does the bundled Apache 
also include a current version of PHP?   Anyone know if ImageMagik is 
included with this release?  (Biggest use of the web server is a web 
gallery that uses a php/imagemagik app)  Anyone think it'd be a good 
time to try out another distro or BSD if they're better suited to a 
headless, no X, server setup?

Thanks and sorry to ask vague questions....
-bp




More information about the TriLUG mailing list