Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
If you say so I'll believe you for linux maybe. I tinkered with the Ransome love Caldera software old school and left the building. Nothing was written back then except the os. I have played with hole punch cards in 70's so I might know just a little something.
I'm a windows guy so I speak from Windows heart.
You have your opinion and I'm sure there are many benefits for putting public IPs on a server box however again in my opinion I strongly disagree with wins server or any exposed production machine. You seem to agree with this MS point so we concur here.
For example any DOS attack (very common) will most centainly use valuable system resources to the point of possible hardware failure. Log files will build insanely fast on a windows machine to the point of no hd space left. The inferior windows firewall cannot compare to astaro. Thus if you have a high traffic site(s) that are not load balanced you could be rebuilding from scratch. I have vast experience with public ip utilized on leased dedicated servers & co located. I have watched CPU load go to 50% straight as attacks were stopped. So I ask the question Why do this? Some kid can just stress test your exposed public machine non stop. If it's simple non important stuff then fine but not me. I've learned.
Thus, using astaro as a backup ok fine but I rather it be in the front line rather than depending upon using any software based firewall in conjunction with OS. Im not saying you.. but from my experience I did this years ago.
(I used several IBMS blackice as primary at hosted colocated internet company and results were "got ya" its only a matter of time.)
Basically the protection of NAT is removed from that computer and
external hosts can initiate conversations with it (on any port). Network between exterior and interior firewalls are where publicly accessible servers are usually placed. Besides you can get many more LAN IPS from just one public Ip however I see a concern with abuse and spamhaus blacklisting IP with this method.
Public IP addresses are used only for communication with external world so kiddies can see you at all times.
Linux is the underdog of hackers so you have time maybe forever but if it become popular watch out.
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow