Web Hosting Talk







View Full Version : Crazy idea for a simple internal firewall?


adrnlnrsh
04-10-2003, 11:11 AM
First off, please don't flame me if this idea is crazy.

I am colocating my first server that I am going to build this weekend. I am paying for colo space by the machine, so for now I will be able to afford one machine at the colo.

I am building into a tower case and I will have a lot of extra room. I will be running a tight ship on the server with ipchains, etc. I will do my best to keep up with security updates and everything else running a server entails.

My question is, can I install a very small linksys router inside the server case to provide additional security to my server?

I am aware of heat issues, the linksys router is spec'ed to up to 105 F operating environment. I am aware the wiring might be interesting to achieve. I am also aware that these little routers offer minimal security and that they were designed for home/DSL/Cable use.

However, I want to know: will this little router provide at least minimal additional security for my server?

I have a feeling I can pull off the engineering aspect of installing the router inside the case and keeping it cool, but if these little routers are completely worthless for security, or if there is some reason the router won't function in this fashion, I won't waste my time. My home linksys router has a plethora of options like port forwarding/filtering and stuff that would seem to be configurable for my purposes.

Thank you for any help.

Spingen
04-10-2003, 11:20 AM
What is wrong with just securing the box normally? What is adding a phyiscal router/firewall going to help you do that you couldn't just do without it?

adrnlnrsh
04-10-2003, 11:28 AM
Thank you for your answer/question. You are implying that a router is useless as a firewall (and I am guessing is only needed for multiple machines)?

I intend to run as secure a box as I can. I am just looking for additional security outside of the normal server software stuff.

Thanks again.

Spingen
04-10-2003, 11:41 AM
You can secure a server quite well without the need for additional hardware. Look into hardening the operating system and properly setting up a firewall. Also make sure patches are always applied promptly and everything is up to date. A router/firewall is not going to take care of these.

neil
04-10-2003, 04:18 PM
what happnes when the router/firewall/whatever you put inside the case fails and you can't access your machine? The host reboots the machine but will that reboot the router/firewall?

It's an interesting idea but I'd probably stick witht the traditional mehtods.

adrnlnrsh
04-10-2003, 04:31 PM
I seem to be getting the feeling that this is not really worth attempting, but for the record if the router fails I could simply ask the people at the colo to unplug the RJ45 going to the router (accessible on the outside of the case via extension cables to the empty pci panels in the back of the tower) and plug it instead into my machine's "normal" RJ45 port. Since my machine will be using its own security measures (see above posts) losing the router would just be annoying, but not devastating.

My colo (theplanet.com) gives me free "hands and eyes" so I am assumming unplugging two cables then plugging in one of them (leaving one dangling) would be simple and free. I am only hosting one machine at the moment, so no real network loss would occur (aside from the time it takes to realize the machine is down and make a phone call/support request).

From that point I would just have a small paperweight occupying one of my empty 5.25" bays.

Anyways, from the response I got here, there is no security benefit to using a router in this fashion.... is this right?!

matt2kjones
04-10-2003, 05:22 PM
Well i dont, personally, think that it will give u any extra security.

i mean, if u can setup a firewall on the machine which is secure and tight, then the router wont really serve any purpose