Koozali.org: home of the SME Server

Setup Question

Offline gavan_white

  • **
  • 29
  • +0/-0
Setup Question
« on: July 18, 2016, 01:44:08 PM »
Hi, I am new to the forum. I have used SME Server for some years as a server-gateway after my modem. Unfortunately, after an upgrade to VDSL, I can't get a modem that will bridge properly, also running all traffic through SME seemed to be a bottleneck.

I have changed the server to server only and forwarded the ports I need to it and use it as a proxy for other computers that need to access these ports. This works well, but I am unsure about the safety of this. The rest of my network gets direct access to the modem otherwise.

My problem is that I don't know whether I am safe port forwarding to the SME in server only mode (single ethernet) or whether I should set it up as sever gateway mode for these port forwarded events eth0 to the modem and eth1 to the rest of the lan. I assume the firewall is best in the latter setup.

Thanks for any help.

Offline Stefano

  • *
  • 10,894
  • +3/-0
Re: Setup Question
« Reply #1 on: July 20, 2016, 09:26:02 AM »
Which version are you running?
I'll move this post in the right place once you answer

Offline gavan_white

  • **
  • 29
  • +0/-0
Re: Setup Question
« Reply #2 on: July 20, 2016, 09:55:13 AM »
Thanks. I am using 9.1.

Offline Stefano

  • *
  • 10,894
  • +3/-0
Re: Setup Question
« Reply #3 on: July 20, 2016, 10:17:28 AM »
Moving to SME Server 9.x section

Offline Stefano

  • *
  • 10,894
  • +3/-0
Re: Setup Question
« Reply #4 on: July 20, 2016, 10:18:59 AM »
I don't see any security issue.. there are zillions of SME running like yours out there :-)

Offline janet

  • *****
  • 4,812
  • +0/-0
Re: Setup Question
« Reply #5 on: July 20, 2016, 10:31:35 AM »
gavan_white

Quote
My problem is that I don't know whether I am safe port forwarding to the SME in server only mode (single ethernet) or whether I should set it up as sever gateway mode for these port forwarded events eth0 to the modem and eth1 to the rest of the lan. I assume the firewall is best in the latter setup.

Either server only or server gateway mode is OK, they both expose ports/services on your sme server to the Internet.

In server only mode you rely on the modem/router to do the firewall functions, whereas in server gateway mode, sme server acts as the firewall.

Which firewall is better, opinions will vary. A regularly updated sme server will use the latest kernel version & likely be more secure as a result, whereas many users may not update their modem firmware.

Better is an interpretive word, in some ways the sme server firewall could/would be considered better than a regular modem, but if your modem/router is a specialised firewall device, then that may well be better.
Functionality & ease of use will also affect a users determination of which is better.
Where sme server requires more expert knowledge to configure the firewall for specialised requirements using a command line interface, a modem with a nice GUI interface may well do the same thing but be easier to configure, & therefore be considered better, due to the GUI interface being easier for a non expert to use.
Please search before asking, an answer may already exist.
The Search & other links to useful information are at top of Forum.

Offline gavan_white

  • **
  • 29
  • +0/-0
Re: Setup Question
« Reply #6 on: July 20, 2016, 10:45:19 AM »
Thanks every body. This does make me feel more relaxed. My concern was that port forwarding from my modem would mean there was no firewall on those ports and wasn't sure if the server only mode did any checking of LAN traffic.

I think I might feel "better" (more comfortable) going server-gateway giving me a firewall to include the forwarded ports.

I honestly believe that SME server is the best thing I have ever added to my home network. I have been using it since the e-smith days and relied heavily on the contribs and howtos to make things work. I just have never posted. Will be donating soon.

Thanks.

Offline janet

  • *****
  • 4,812
  • +0/-0
Re: Setup Question
« Reply #7 on: July 20, 2016, 02:50:54 PM »
gavan_white

The modem has a firewall, you used it to forward the ports.
Please search before asking, an answer may already exist.
The Search & other links to useful information are at top of Forum.

Offline gavan_white

  • **
  • 29
  • +0/-0
Re: Setup Question
« Reply #8 on: July 20, 2016, 03:33:15 PM »
Thanks Janet. That is correct, my mix up.