Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
PostPosted: Fri Dec 18, 2009 5:55 pm 
Offline

Joined: Fri Dec 18, 2009 3:49 pm
Posts: 1
I'd like to use one Linode as a proxy server for another. I'm planning to have a "private" server A, accessible only to me and running only some utility stuff, and a "public" server B, accessible to a whole bunch of people, including some with admin privileges whom I don't fully trust. I'd like all of B's Internet traffic to be sent through A, so that I can do stuff like preventing it from sending email. Of course, it might suffice simply to block certain ports, which might be more possible but also would be less flexible. What think ye?


Top
   
 Post subject:
PostPosted: Sat Dec 19, 2009 2:14 pm 
Offline
Senior Member
User avatar

Joined: Sun Jan 18, 2009 2:41 pm
Posts: 830
If they have root access on B, there's no way to force their network traffic to go through A. If they don't have root access on B, then you can control network traffic using B's firewall. So while there might be practical advantages to doing things as you propose, I don't see any security advantages.


Top
   
 Post subject:
PostPosted: Mon Dec 21, 2009 1:55 pm 
Offline
Senior Member
User avatar

Joined: Tue May 26, 2009 3:29 pm
Posts: 1691
Location: Montreal, QC
Actually, you *CAN* force them. If one of the VPS only has a private IP address bound, then the only way they can access that machine is from another VPS on your account.

Why can't they get around this? Because the only way to get from that machine to the net (other than through the other VPS) would be to add the public IP and reboot. But since they have no way of knowing the public IP (there are a rather large number of possibilities), there's nothing that they can do about it.


Top
   
 Post subject:
PostPosted: Mon Dec 21, 2009 3:50 pm 
Offline
Senior Member

Joined: Mon Oct 27, 2008 10:24 am
Posts: 173
Website: http://www.worshiproot.com
All they'd have to do it hit up the DHCP server for one.

~JW


Top
   
 Post subject:
PostPosted: Tue Dec 22, 2009 1:19 pm 
Offline
Senior Member
User avatar

Joined: Tue May 26, 2009 3:29 pm
Posts: 1691
Location: Montreal, QC
In which case, ask Linode to remove the IP from the Linode. There won't be anything for the DHCP server to return.


Top
   
 Post subject:
PostPosted: Thu Dec 24, 2009 2:39 am 
Offline
Senior Member

Joined: Sat May 03, 2008 4:01 pm
Posts: 567
Website: http://www.mattnordhoff.com/
Guspaz wrote:
If one of the VPS only has a private IP address bound, then the only way they can access that machine is from another VPS on your account.


Or any other Linode with a private IP in the same data center...


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 3 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group