Koozali.org: home of the SME Server

Switch to Server-Only and use IPCOP as Gateway/Firewall

Offline steever

  • *
  • 185
  • +0/-0
    • Open-Sesame
Switch to Server-Only and use IPCOP as Gateway/Firewall
« on: January 12, 2005, 03:56:43 AM »
At the moment we use SME 6.0.1 as our Gateway/Server.  I would like to put IPCOP in front as firewall/gateway, and then use the SME as a file/server only.

Anybody done this? Anyone had trouble or foresee trouble?

Thanks.
Saving the world ... one server at a time.

kangkc

Switch to Server-Only and use IPCOP as Gateway/Firewall
« Reply #1 on: January 12, 2005, 05:47:42 AM »
No problem at all. This is exactly what we have. IPCOP front the outside world, and placing SME Server in the DMZ.

We have been running in this configuration for over a year now and suffer zero down time (other than scheduled maintenance down time).

Mail/Web traffic are port forwarded to SME Server in the DMZ.

Good Luck.

Offline briank

  • ****
  • 146
  • +0/-0
Switch to Server-Only and use IPCOP as Gateway/Firewall
« Reply #2 on: January 12, 2005, 11:02:59 AM »
I have contemplated this but can't see any advantage - SME has a perfectly acceptable firewall. Can you enlighten me?
Regards
Brian

Offline BoZz

  • ***
  • 48
  • +0/-0
Switch to Server-Only and use IPCOP as Gateway/Firewall
« Reply #3 on: January 12, 2005, 01:14:46 PM »
I have servers in both config's and both work well with out problem  :-) contribs server is good enough with updates, the firewall is great. I only use IPCOP when Contribs is being used as a file server that must be real secure. Then the extra hop to the outside world is better. I don't DMZ, only open and forward the ports you need, normally 22 for SSH / some times PPTP. But if only for admin work just SSH, your can tunnel the rest through your SSH session EG server-manager, etc.

   ;-)