Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
 Post subject: Am I nuts?
PostPosted: Wed Feb 22, 2006 4:37 pm 
Offline
Senior Newbie

Joined: Wed Feb 22, 2006 4:14 pm
Posts: 17
I run Gentoo on 3 workstations and a server on my LAN. I would like to setup a Linode running Gentoo, just because it seems easy.

I want to run Tomcat 5, Apache, IMAP mail, a possibly some video streaming.

Although, I'm totally confortable with Gentoo, and I'm a developer, I don't have much website admin experience. Am I getting in over my head with Apache and Mail, or is this the hosting service I've been looking for?

For example, I can easily install Apache

emerge -a apache

But, if I do this, I then have to configure Apache and make it secure. Is this going to take up too much time?

Can anyone give some advice from experience?

Thanks


Top
   
 Post subject:
PostPosted: Wed Feb 22, 2006 8:15 pm 
Offline
Junior Member

Joined: Sun Feb 05, 2006 7:42 pm
Posts: 22
Location: Sydney, Australia
Quote:
Although, I'm totally confortable with Gentoo, and I'm a developer, I don't have much website admin experience. Am I getting in over my head with Apache and Mail, or is this the hosting service I've been looking for?


One can get into Apache without too much trouble. There is a lot to configure, but you can get a basic webserver going relatively quickly and there is a lot of help on the web on how to configure it.

Mail, however, is a bugbear. It is like walking into a minefield.. something you should do with trepidation and hopefully someone with experience beside you! It can be rewarding, however, so if you do choose to get into mail just keep your eyes wide open and learn as much as you can!


Top
   
 Post subject:
PostPosted: Wed Feb 22, 2006 10:33 pm 
Offline
Senior Newbie

Joined: Wed Feb 22, 2006 4:14 pm
Posts: 17
Thanks for the reply. I did setup gmail once years ago on my home hosted system. And, there are some good wiki mail and even virtual server setup docs. I'll post here, in case someone else will benefit.

http://gentoo-wiki.com/HOWTO_Linux_Virt ... ing_Server
http://www.gentoo.org/doc/en/virt-mail-howto.xml

I'm starting to talk myself into jumping in. But ....

What about Security? Basically, Apache, Mail, Tomcat, and the rest are all fun and games until you are outside your LAN. I'd hate to loose sleep because some port scanning script kiddies are pounding on my system for a password.

Any chance Linode helps with security like this?

Thanks


Top
   
 Post subject:
PostPosted: Thu Feb 23, 2006 6:19 am 
Offline
Senior Member
User avatar

Joined: Fri Oct 24, 2003 3:51 pm
Posts: 965
Location: Netherlands
genode wrote:
Any chance Linode helps with security like this?


Linode only does filtering in layers 2 and 3 to stop network screwups. The Planet (Dallas datacentre) blocks some 'popular' exploit ports. HE (Fremont datacentre) doesn't block anything.

Nearly all Linode users run a netfilter/iptables firewall on their machine. FireHOL is an excellent firewall generator which configures iptables to do stateful packet filtering - you decide who accesses what on your machine.

_________________
/ Peter


Top
   
 Post subject:
PostPosted: Thu Feb 23, 2006 3:49 pm 
Offline
Senior Newbie

Joined: Wed Feb 22, 2006 4:14 pm
Posts: 17
pclissold wrote:
genode wrote:
Any chance Linode helps with security like this?


Nearly all Linode users run a netfilter/iptables firewall on their machine.


Right, thanks for the reply. Good to know what I'm getting into.

I'm thinking I'll run just httpd, imap, a firewall and i'll use syslog-ng/stunnel to securely write logs to my machine in my LAN here at home.

Here's a helpful link

http://www.gentoo.org/doc/en/security/s ... ndbook.xml


Top
   
 Post subject:
PostPosted: Sun Mar 12, 2006 6:55 am 
Offline
Senior Member

Joined: Sat Dec 04, 2004 5:36 pm
Posts: 145
genode wrote:
pclissold wrote:
genode wrote:
Any chance Linode helps with security like this?


Nearly all Linode users run a netfilter/iptables firewall on their machine.


Right, thanks for the reply. Good to know what I'm getting into.

I'm thinking I'll run just httpd, imap, a firewall and i'll use syslog-ng/stunnel to securely write logs to my machine in my LAN here at home.

Here's a helpful link

http://www.gentoo.org/doc/en/security/s ... ndbook.xml


I'm currently running Gentoo (and have done so for over a year on the Linode) but will soon switch to Debian because of lower overhead. I.e., no source build overhead on the Linode.

Still, it's worked well for me so far. I do indeed run an iptables-based firewall, syslog-ng, amongst other goodies, and it has worked out great. (Along with Apache v2 + SSL, postfix for email, etc.)

If you need pointers with iptables rules, just post in a new thread. I'd be more than happy to assist, or the other users here. Also, if you're new to iptables, might want to look at tools like Shoreline (aka 'Shorewall') which is an OSS tool to build and maintain iptables configs.

Cheers.


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 6 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group