Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
 Post subject:
PostPosted: Thu Sep 11, 2003 6:50 pm 
Offline
Senior Member

Joined: Sat Jun 28, 2003 12:02 am
Posts: 66
Website: http://kenny.aust.in
adamgent wrote:
It is more that the node can not be accessed via the internet.
...
Under a standard server set-up, if you wanted a DB server that can not be accecss by any method over the internet, you would set-up a seperate lan for internal traffic between the web servers and the database serves. The web servers been accessible over the internet via the external network.


If that seperate lan is still attached to the same physical network, how is this any different then just removing the routes on your DB server and a using good set of iptables? They both would be accessible from any device plugged into the lan (other linodes), and both wouldn't be accessible from any device outside the lan (internet). Am I missing something?

kenny


Top
   
 Post subject:
PostPosted: Thu Sep 11, 2003 6:56 pm 
Offline
Senior Member
User avatar

Joined: Mon Jun 23, 2003 1:25 pm
Posts: 260
It isn't

The standard method is to usual set-up a private lan, between just your servers, so only you would have access to them, if you where colo servers, or had a bunch of dedicated servers, it is also to do with bandwidth usage.

The way the set-up is at linode.com it would not matter either way.

Adam


Top
   
 Post subject:
PostPosted: Fri Sep 12, 2003 12:45 am 
Offline
Junior Member
User avatar

Joined: Thu Sep 11, 2003 3:11 pm
Posts: 36
Website: http://www.bod.org
Location: San Jose, CA
Just another datapoint: I created my first Linode this morning, booted it briefly to check I could ssh into it, and then shut it down again. Nothing in the outside world knows it exists yet.

But still I have 514KB of incoming traffic in a few hours, to a brand new linode that's 'off' and no-one knows about. Clearly that's not right :)

Chris, do you have an e.t.a for a fix for this?

Paul


Top
   
 Post subject:
PostPosted: Fri Sep 12, 2003 4:30 am 
Offline
Linode Staff
User avatar

Joined: Tue Apr 15, 2003 6:24 pm
Posts: 3090
Website: http://www.linode.com/
Location: Galloway, NJ
PaulC wrote:
Chris, do you have an e.t.a for a fix for this?

Paul

I can't give you an ETA yet, but I have been messing around with a solution...

-Chris


Top
   
 Post subject:
PostPosted: Sat Sep 13, 2003 12:13 am 
Offline
Senior Newbie

Joined: Mon Sep 08, 2003 2:54 am
Posts: 9
In an effort to minimize traffic I have set up shorewall, to DROP packets I don't want, this should half 'idle' traffic as it doesn't send a responce. It's really weird, I was getting heaps of pings from *.hotmail.com hosts. Now I don't reply to them. Im also using ipfm to log traffic, by source.


Top
   
 Post subject:
PostPosted: Mon Sep 15, 2003 5:56 pm 
Offline
Linode Staff
User avatar

Joined: Tue Apr 15, 2003 6:24 pm
Posts: 3090
Website: http://www.linode.com/
Location: Galloway, NJ
I added some network filtering so the UDP port 137 traffic should no longer be running wild.

I also improved the network monitoring. You should only get ICMP ping (and possibly a packet or two to port 80) from the host your Linode is on every minute. Previously, every host was blindly monitoring every IP, regardless of where the Linode was.

Still working on the "non-local-only traffic accounting" fix.

-Chris


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 7 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group