[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y ] [Search | Free Show | Home]

Dedicated Server Setup

This is a blue board which means that it's for everybody (Safe For Work content only). If you see any adult content, please report it.

Thread replies: 11
Thread images: 1

File: watchguard.jpg (11KB, 450x187px) Image search: [Google]
watchguard.jpg
11KB, 450x187px
When setting up a dedicated server at home that will be used by people outside my home, should I use a secondary router that is separate from my primary one which people in my house use?

Trying to secure it so that the users of the internet around me will not be affected or infected.

At the moment, I'm using a RTN65U router.
>>
Setup VLANS and only allow the server to be accessed and dont allow the Server VLAN to be able to access the House VLAN
>>
>>59719284
What services are you going to run on the server? Most US isp's blacklist their residential ip addresses. So if you're wanting to do mail it's gonna end up in the spam box.
>>
>>59719284
we have a watchguard firewall in our office. I don't trust it.

Thoughts?
>>
>>59719695
A dedicated game server at the moment but I'm doing it more as a stress test and I am trying to learn from it
>>
>>59719720
You have the wrong focus. You shouldn't be worried about stress testing. You get compromised and your server could end up hosting child porn. It can be an expensive learning process.

Anyways more details on the games you plan to host will make it easier for people to give specific advice.
>>
>>59719957
Not OP but are there some good articles on locking down headless servers? I know this is an oxymoron, but what about a webgui tool for those less experienced to manage the server?
>>
>>59719713
It's fine if you manage it yourself
It's probably not fine if you have a service contract with an external company.

They can easily grab all your logs without you even knowing it.

Otherwise, watchguard is a decent firewall. Never had any issues
>>
What you want is a router with 3 network ports. One wan, one LAN, one DMZ. Dmz network is not linksys router kind where all traffic gets forwarded, rather its a segregated network.

LAN->dmz: allow all
DMZ->LAN: deny all
Wan->DMz: allow specific ports to a specific ip

This way if your web server in the DMz get hacked, they won't have access to your internal network.

If you're really paranoid, and you should be, block all DMz->wan traffic so DMz systems can't get to the internet except where allowed. This will protect from reverse shell attacks and attacks that need your server to download something from somewhere.
>>
>>59719284
There are a lot of things you could do to secure it. Getting a second router dedicated to the server is only useful if you also buy a separate internet connection for the server. That would be nice because it would be completely logically separated from your home network. Otherwise you should look into firewalls, vlans, auto-updates, and if you're really paranoid you could get an IDS or IPS.
>>
>>59720871
Also this. A DMZ is a great idea. I can't believe I forgot to mention that.
Thread posts: 11
Thread images: 1


[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y] [Search | Top | Home]

I'm aware that Imgur.com will stop allowing adult images since 15th of May. I'm taking actions to backup as much data as possible.
Read more on this topic here - https://archived.moe/talk/thread/1694/


If you need a post removed click on it's [Report] button and follow the instruction.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com.
If you like this website please support us by donating with Bitcoins at 16mKtbZiwW52BLkibtCr8jUg2KVUMTxVQ5
All trademarks and copyrights on this page are owned by their respective parties.
Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
This is a 4chan archive - all of the content originated from that site.
This means that RandomArchive shows their content, archived.
If you need information for a Poster - contact them.