Re: Need an advise about isolating a host in the DMZ

2002-12-21 Thread Haim Ashkenazi
On Sat, 2002-12-21 at 13:24, Glen Mehn wrote: > Nick Boyce wrote: > > > > pureftpd rocks. It's built to support most of the ftp commands, and has > super simple configuration. Actually I've already selected vsftpd. since I only need it for anonymous ftp (it's going to be a mirror for GNU, sunfreew

Re: Need an advise about isolating a host in the DMZ

2002-12-21 Thread Glen Mehn
Nick Boyce wrote: On Wed, 18 Dec 2002 14:19:52 +0200 (IST), <[EMAIL PROTECTED]> wrote: I'm thinking about using qmail as the smtp(only have access from the mail relay server)/pop3 server (from what I've read this is a very secure software). any suggestions about what ftp server should I run

Re: Need an advise about isolating a host in the DMZ

2002-12-21 Thread Haim Ashkenazi
On Sat, 2002-12-21 at 13:24, Glen Mehn wrote: > Nick Boyce wrote: > > > > pureftpd rocks. It's built to support most of the ftp commands, and has > super simple configuration. Actually I've already selected vsftpd. since I only need it for anonymous ftp (it's going to be a mirror for GNU, sunfreew

Re: Need an advise about isolating a host in the DMZ

2002-12-21 Thread Glen Mehn
Nick Boyce wrote: On Wed, 18 Dec 2002 14:19:52 +0200 (IST), <[EMAIL PROTECTED]> wrote: I'm thinking about using qmail as the smtp(only have access from the mail relay server)/pop3 server (from what I've read this is a very secure software). any suggestions about what ftp server should I run (

Re: Need an advise about isolating a host in the DMZ

2002-12-20 Thread Nick Boyce
On Wed, 18 Dec 2002 14:19:52 +0200 (IST), <[EMAIL PROTECTED]> wrote: >I'm thinking about using qmail as the smtp(only have access from the mail >relay server)/pop3 server (from what I've read this is a very secure >software). any suggestions about what ftp server should I run (is proftpd >secure e

Re: Need an advise about isolating a host in the DMZ

2002-12-20 Thread Nick Boyce
On Wed, 18 Dec 2002 14:19:52 +0200 (IST), <[EMAIL PROTECTED]> wrote: >I'm thinking about using qmail as the smtp(only have access from the mail >relay server)/pop3 server (from what I've read this is a very secure >software). any suggestions about what ftp server should I run (is proftpd >secure e

Re: Need an advise about isolating a host in the DMZ

2002-12-19 Thread Haim Ashkenazi
Thanx, everybody. As always you've been a great help :) Bye -- Haim

Re: Need an advise about isolating a host in the DMZ

2002-12-19 Thread Haim Ashkenazi
On Wed, 2002-12-18 at 15:11, Blars Blarson wrote: > In article <[EMAIL PROTECTED]> [EMAIL PROTECTED] writes: > >create a second DMZ, but that would cost me the lost of three ip's, so > >I'm trying to figure out ways to isolate him without putting it in > >another subnet. > > There's no need to use

Re: Need an advise about isolating a host in the DMZ

2002-12-19 Thread Haim Ashkenazi
Thanx, everybody. As always you've been a great help :) Bye -- Haim -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Need an advise about isolating a host in the DMZ

2002-12-19 Thread Haim Ashkenazi
On Wed, 2002-12-18 at 15:11, Blars Blarson wrote: > In article <1040204536.12811.100.camel@parker> [EMAIL PROTECTED] writes: > >create a second DMZ, but that would cost me the lost of three ip's, so > >I'm trying to figure out ways to isolate him without putting it in > >another subnet. > > There'

Re: Need an advise about isolating a host in the DMZ

2002-12-18 Thread Rick Moen
Quoting [EMAIL PROTECTED] ([EMAIL PROTECTED]): > I'm thinking about using qmail as the smtp(only have access from the mail > relay server)/pop3 server (from what I've read this is a very secure > software). any suggestions about what ftp server should I run (is proftpd > secure enough)? These fil

Re: Need an advise about isolating a host in the DMZ

2002-12-18 Thread Blars Blarson
In article <[EMAIL PROTECTED]> [EMAIL PROTECTED] writes: >create a second DMZ, but that would cost me the lost of three ip's, so >I'm trying to figure out ways to isolate him without putting it in >another subnet. There's no need to use extra IPs just to set up another subnet. Just use the same I

RE: Need an advise about isolating a host in the DMZ

2002-12-18 Thread haim
>> Hi >> >> I have a host in my DMZ that has both anonymous ftp and pop3 >> ports open >> (this can't be changed). since I really don't trust this setup, I was >> thinking about ways to isolate this host so no one who break to this >> computer, can access other computers on the DMZ (although other

Re: Need an advise about isolating a host in the DMZ

2002-12-18 Thread Rick Moen
Quoting [EMAIL PROTECTED] ([EMAIL PROTECTED]): > I'm thinking about using qmail as the smtp(only have access from the mail > relay server)/pop3 server (from what I've read this is a very secure > software). any suggestions about what ftp server should I run (is proftpd > secure enough)? These fil

Re: Need an advise about isolating a host in the DMZ

2002-12-18 Thread Adrian Phillips
> "Haim" == Haim Ashkenazi <[EMAIL PROTECTED]> writes: Haim> Hi I have a host in my DMZ that has both anonymous ftp and Haim> pop3 ports open (this can't be changed). since I really Haim> don't trust this setup, I was thinking about ways to isolate Haim> this host so no one who

Re: Need an advise about isolating a host in the DMZ

2002-12-18 Thread Blars Blarson
In article <1040204536.12811.100.camel@parker> [EMAIL PROTECTED] writes: >create a second DMZ, but that would cost me the lost of three ip's, so >I'm trying to figure out ways to isolate him without putting it in >another subnet. There's no need to use extra IPs just to set up another subnet. Jus

RE: Need an advise about isolating a host in the DMZ

2002-12-18 Thread haim
>> Hi >> >> I have a host in my DMZ that has both anonymous ftp and pop3 >> ports open >> (this can't be changed). since I really don't trust this setup, I was >> thinking about ways to isolate this host so no one who break to this >> computer, can access other computers on the DMZ (although other

Re: Need an advise about isolating a host in the DMZ

2002-12-18 Thread Javier Fernández-Sanguino Peña
On Wed, Dec 18, 2002 at 11:42:16AM +0200, Haim Ashkenazi wrote: > Hi > (...) > > I thought about 2 solutions so far: > 1. putting iptables on all the other computers in the DMZ. > 2. connecting this host to another VLAN and set this >configuration on the switch (I hav

RE: Need an advise about isolating a host in the DMZ

2002-12-18 Thread DEFFONTAINES Vincent
> Hi > > I have a host in my DMZ that has both anonymous ftp and pop3 > ports open > (this can't be changed). since I really don't trust this setup, I was > thinking about ways to isolate this host so no one who break to this > computer, can access other computers on the DMZ (although other > co

Re: Need an advise about isolating a host in the DMZ

2002-12-18 Thread Adrian Phillips
> "Haim" == Haim Ashkenazi <[EMAIL PROTECTED]> writes: Haim> Hi I have a host in my DMZ that has both anonymous ftp and Haim> pop3 ports open (this can't be changed). since I really Haim> don't trust this setup, I was thinking about ways to isolate Haim> this host so no one who

Re: Need an advise about isolating a host in the DMZ

2002-12-18 Thread Javier Fernández-Sanguino Peña
On Wed, Dec 18, 2002 at 11:42:16AM +0200, Haim Ashkenazi wrote: > Hi > (...) > > I thought about 2 solutions so far: > 1. putting iptables on all the other computers in the DMZ. > 2. connecting this host to another VLAN and set this >configuration on the switch (I hav

RE: Need an advise about isolating a host in the DMZ

2002-12-18 Thread DEFFONTAINES Vincent
> Hi > > I have a host in my DMZ that has both anonymous ftp and pop3 > ports open > (this can't be changed). since I really don't trust this setup, I was > thinking about ways to isolate this host so no one who break to this > computer, can access other computers on the DMZ (although other > co