Koozali.org: home of the SME Server

Using Dyndns.org in single server mode ( V5 )

Herve

Using Dyndns.org in single server mode ( V5 )
« on: December 28, 2001, 07:11:33 PM »
Hi everybody !

I am a newbie trying to configure the version 5 of the server ...

My question / problem is following :

I am using the server that is connected to the internet via ADSL .
Since the ADSL router is making the PPPoE connection to the internet, and has  its own firewall, I installed the server as a single server ( Only one ETH connection ).

In such a case, I cannot use the internal Dyndns.org client application that reads out the Wan IP address onto the Ethernet connection.
On top of that, the internal client applications seems not to be able to update the MX record. ( Other posts in the phorum )

So I found out some other client application, in RPM.
From doc, application should be able to find WAN IP address from HTTP connection to specifc sites.
It is called : ddclient 3.6.1. (www.dyndns.org )

If somebody knows that, and perhaps already mades the exercise, it can be helpfull to me. I am not a deep Linux specialist !.

All ideas, suggestions are welcome.

Thanks in advance.

Judy Morgann

Re: Using Dyndns.org in single server mode ( V5 )
« Reply #1 on: January 07, 2002, 08:23:42 PM »
hi,

there are two problems easy to solve :) first you have to activate portforwarding/portmapping on your adsl router that he forwards all request from the
outside to your e-smith internal ip. to get the external ip of your router there are some scripts that you can install on your e-smith server. they recognize the routers wan ip. it´s dependable on your routers model.
another way is to make a traceroute from your e-smith server to an internet address - the first ip that is shown is your routers external ip.

greetings
judy

Alexander Ziemann

Re: Using Dyndns.org in single server mode ( V5 )
« Reply #2 on: January 18, 2002, 10:18:49 PM »
Hi,

if you can afford to, you should better tear down your adsl-router, give the e-smith server a second nic and run it in gateway/server mode:

1. Most hardware routers do not have sufficent firewalling/port-filtering.
2. Most hardware routers are easy to hack.
3. The implementation of firewalling and port-forwarding on your router will -by means of security- demand for a DMZ (demilitarized zone), in which you then better should put your e-smith server. This will result in demand for a second e-smith server for fileserver purposes in internal net!
4. This all will make your network uncomfortable and hard to administer.
5. I sold my dsl-router and i am happy with it.

There is (besides of php-nuke) no known problem with e-smith in the security field. By means of "normal" security one e-smith server running permanent adsl in gateway-server mode is more secure than e.smith + router.

Just my experience...

Have fun.

Alex