Dual setup for internet and internal access

Goal: To set up an Xserve that is both hosting public web sites and internal websites. The server is currently connected to the internet via ethernet 1 and to our internal network via ethernet 2. It serves as a backup failover for our main web server and hosts an internal wiki. The wiki is getting more sensitive company information so we want to cut it off from outside access and guarantee that it cannot be hacked or otherwise seen. Someone mentioned a solution using partitioning of some kind to achieve this separation. I haven't been able to find information on this. Can anyone tell me more about what this may be or suggest a setup that will accomplish the same security.

Here, you have two NICs within one security context.
A security breach made via one NIC can generally gain access to another NIC within the context of a single operating system. Once the [security of the box is breached|http://labs.hoffmanlabs.com/node/1214] sufficiently to cause you problems (whether data exposures, deletions, defacement or otherwise), then the entire box is generally considered to be untrustworthy.
If the breach arrives via http port 80 (and that is a typical web server breach), then (once the breach is made) the box itself is compromised. The firewall block here doesn't get you the degree of isolation provided by a DMZ; a breach via port 80 inward or one of these recent browser-based attacks on the firewall aren't necessarily blocked. (Whether the particular web environment is directly vulnerable to a breach is another and open question. Some environments can be more vulnerable to others, but there's the common assumption that all web-facing and internet-facing environments can potentially be vulnerable. That also ties back to how the box is managed and monitored, and how fast a breach can be detected and isolated and sealed and cleaned up.)
Some operating systems feature technologies known as sandboxes or jails or such, and sandboxes (and jails) are not AFAIK officially available on Mac OS X Server. These are part-way between the default configuration and what's provided by operating as a VM guest. If you really want to learn the innards of the configuration sufficiently, you might be able to get a jail or sandbox or such going, but then tossing another Mac Mini at the problem solves it in what is usually a more supportable fashion than getting a sandbox or jail going and maintaining the configuration over Mac OS X Server patches and upgrades, and application installations and upgrades, and thus at lower cost.
The approach using a VM tries to avoid extending the exposure by requiring the attacker to breach the underlying VM to get further from the box, and approaches based on a DMZ and on multiple boxes also try to contain or firewall a compromised system.

Similar Messages

  • Configure a sharepoint 2013 site for external and internal access

    I need to configure a local install of sharepoint 2013 so that users can access it internally and externally using windows/AD authentication. The internal and external addresses are different.
    I have bound an external ip to the domain for external access.
    I have created Alternate Access mapping, and bound the host header but I get a file not found message for external access.
    Have I missed something here? why the error and how can it be fixed. Step by step process would be appreciated.

    Hi Luis,
    According to your description, my understanding is that the error occurred when accessing the site externally.
    The most common cause for this is that the IIS host header is configured incorrectly. The 404 will appear because we are hitting a different IIS web site and not the one we are intended to.
    Here is a similar issue for you to take a look:
    http://stackoverflow.com/questions/14953322/sharepoint-2013-404-not-found-while-accessing-site-collection-from-outside
    More references:
    http://technet.microsoft.com/en-us/library/cc261814(v=office.15).aspx
    http://technet.microsoft.com/en-us/library/cc263208(v=office.15).aspx
    Best regards.
    Thanks
    Victoria Xia
    TechNet Community Support

  • I just repaired my sons macbook and I need to test it. Can I start it and skip the setup for internet and account names?

    My son's MacBook pro needed a new hard drive.  He is out of state for a month.
    I want to test it to make sure it has been fixed, but I cannot get past the start screens which require
    an owner name, an account name and passwords.  It states the account name cannot be changed once
    entered. I dont want to enter info that might not be his preferences.
    Can I bypass this screen?  There is no "skip"nor "continue" button.
    It wont let me proceed without an entry.  Can I bypass this for now to simple
    run through the basic programs?

    How did you install the OS and which OS version did you install?
    You do need to set up an account. I never enter my address, etc, but usually (when I want to sell a machine with a new install) set up a temporary account "user" with a password of 12345 with as little info as possible (it also helps if it's not connected to the internet at that point because it won't be able to contact Apple's servers. That way you can run it and he can establish another account when is is back.

  • Use airport for internet and ethernet for local?

    Hi. Ive searched around and cant find an answer for this.
    I have a 27" imac connected to my router and all works fine for accessing the internet.
    I have several other devices close by that I want to connect via ethernet. If i connect the imac to another router via ethernet I can browse my local devices but loose internet connectivity. It is as if the imac will suspend the airport connection while the ethernet cable is connected. I don't want my second router to act as a bridge as it doesn't support N speeds.
    Essentially, I want the imac to use airport for internet and the ethernet port for local files.... The only workaround I have is to unplug the ethernet cable from the back of the imac when i want to use the internet. I'm hoping it's just a DNS issue, but cant seem to resolve it.
    I do not need internet connectivity for the other devices and don't see how i can do that without enabling the wireless side of my second router and then creating a bridge...
    Any suggestions?

    It is as if the imac will suspend the airport connection while the ethernet cable is connected.
    The Connection Order on your iMac is set so that if both AirPort and Ethernet are "on", the iMac will give priority to the Ethernet connection.
    If you want to configure your iMac so that it gives priority to an AirPort connection if both AirPort and Ethernet are "on", give this a try:
    Open System Preferences (gear icon on the dock) and open Network
    Click on the small gear icon at the bottom of the connection list on the left
    Click on Set Service Order and drag AirPort to the top of the connection order list
    Click OK, then click Apply
    Now, if both AirPort and Ethernet are active, your iMac will give priority to the AirPort connection. If you want to connect using Ethernet, you will have to turn AirPort off by clicking the fan shaped AirPort icon at the top of your computer screen.

  • Can i use cdma for internet and gsm for phone at a time in Iphone4s?

    Can i use cdma for internet and gsm for phone at a time in Iphone4s?

    No. Phones sold by GSM carriers can't access CDMA at all and phones sold by CDMA carriers can only access GSM if they are a) unlocked and b) in an area where there is not CDMA.
    Best of luck.

  • Dual boot for lion and SL

    BHow do I set up the dual boot for Lion and snow leopard oon the same internal hard disK
    What does Time machine do  under the dual boot?

    I am also considering putting Lion and SL on separate hard drives.
    Since this is an iMac forum, I assume you will use an external drive as the second drive. Use one that connects via firewire, not via USB.
    Both on a single drive -
    OK. Doing it on a single drive means you will need to partition the internal drive. Although this is straight forward, it is always best to back up the existing drive first, just in case. It's a good idea to have a backup on a different drive, anyway.
    To do that, clone the entire internal drive to the external drive.
    I would suggest, though, that you first partition the external drive. I would suggest four equal-size partitions, provided the drive is big enough - at least 1.0TB, though a 2.0TB drive might be better. You can use OS X's disk utility to do that. Go to the Partition page in Disk Utility, select your external driv in the list on the left, then use the Partition Layout menu to select the number of partitions. Set the format to Mac OS Extended (journaled) GUID for all partitions. Click the Apply button.
    The easy way to do the cloning is to use a cloning utility such as Carbon Copy Cloner. Clone the entire internal drive to one of the partitions on the external drive. Then test boot to it (use Startup Disk in System Preferences to do that) to verify the integrity of the clone. At that time I would suggest you change the background design/picture for the desktop to aomething other than the one used on the original drive - this can be a handy visual reminder of which volume you are booted to.
    Then add a partition to the internal drive. To do that, run Disk Utility. Go to the Partition page, select your internal drive in the list on the left, but do not use the Partition Layout menu this time. Instead, click the existing volume in the graphic display, then click the plus ("+") button underneath that display -
    This will add a partition without erasing the existing information - i.e., the drive will end up with two partitions, one of which will contain your original boot volume.
    Use Startup Disk to re-select your original boot violume, and restart back into it.
    Now, clone the original drive again using CCC, but this time to the second partition of the internal drive, the one you just added.
    Boot to that freshly cloned volume to verify it. Then, while still booted to it, install OS X 10.7 Lion onto it.
    This will result in your original Snow Leopard on the first partition of the internal drive, and Lion on the second partition of the internal drive.
    The external drive will have Snow Leopard on one partition, one partition will be empty (available for a clone of Lion if you wish, or use it for extra storage). The remaining two partitions can be used for Time Machine backups - one for Snow Leopard, one for Lion.
    If you want to have each OS on its own hard drive, then you can use the first clone of Snow Leopard to the external to be upgraded to Lion, or upgrade the orignal on the internal drive to Lion. Be sure to boot to the volume to be used for Lion before installing it so that Lion is installed onto the correct boot volume.
    You can then use the empty partition on the internal drive as the backup (or Time Machine) volume for the OS on the external drive, and vice versa. In this arrangement you may need only partition the external into two volumes.
    If you have a different scheme in mind for partitioning, feel free to do that. I don't use Time Machine, so don't have the need to make space for it. Carbon Copy Cloner can be used to do incremental backups after the initial backup - but I don't use that, either. I'm old school - after the inital cloning for backup, I do manual backups of files on the fly.
    Comments -
    * I would suggest keeping both Snow Leopard and Lion on the internal drive. Reason - even though firewire 800 is fast, it is still noticeably slower than an internal drive. OS's on an external drive will run slower than those on an internal drive.
    • I don't like the concept of Time Machine. Amongst other things, it seems to want more space on the target volume than it actually needs; and it is not a bootable replication. A clone of a bootable volume is bootable.
    • It was just a few days ago that I went through the same process as you are planning. One slight difference - I used a 1.0TB external partitioned into 3 equal volumes, since I had no need to allow space for Time Machine. I have Snow Leopard and Lion each on its own partition of the internal drive; and cloned backups of each on the external drive, plus one GP partition on the external drive.
    • If you have not yet downloaded Lion, be prepared for it to take a while; it's almost 4GB in size. Probably be a good idea to defeat sleep for the duration.
    • Cloning takes a while, but not that long - it took 30 minutes to clone 45GB to the external drive, and 45 minutes to clone it to the second internal partition.

  • Change public share access to read only for public and full access to selected users

    Hi, new to the community just purchased a recertified WDMyCloud 2TB after my 2 years old MyBookLive 2TB HD died due to accidental power cable unplugging. I've got everything setup including MiniDLNA by following instructions on this forum and everything is working  exactly as I want it to except public share. I want public share to be set to read only access for public and full access to certain users (just myself at the moment) and having a "upload" folder within this share with full public access to everything in this folder would be a bonus. I tried login in to ftp with root user and removing write permission for public but that blocks me out as well. I'm sure it's possible by doing some majic on SSH but I wouldn't have a clue so hoping someone here would be able to help me out.

    Mr_Khan wrote:
    What i want is public to have read only access to file server. Public as in users who do not have a user account on mycloud. E.g someone who connects to to my home network for the first time and is able to browse and download content from public share. I'm aware of being able to set indivual access to shares for users like full access, read only and no access but public users won't have a user account.Through the My Cloud UI interface what you seek to do is not possible. The public share like all other share folders are an all or nothing affair when using the adminstration UI. When using the administration UI you do not have granular control on shared folders to limit non users to read only access or set permission levels for subfolders. The workaround to do what you seek and have the public folder set for read only is to change the folder settings via SSH. It may take some work to set the folder security so that users can read/write to the public folder while the guests only have read access. However, if you reboot the WD My Cloud or update the WD My Cloud firmware those settings may be reset back to the default settings where the entire public folder is read/write for all. There are way to prevent this but again it will take a bit of coding to do so via SSH. See this link (even though its for the WD My Book Live) for a starting point on how to use SSH to change the permission levels on the public folder. Another option if one doesn't go the SSH route is to turn off public sharing for the public folder then create a "guest" user account and give that "guest" account read only access to the public folder while all other user accounts have full read/write access.

  • Assign wifi for internet and Lan1 for internal network

    I have a lan connection to my office which it has access to internet by proxy and I have wifi to access directly to internet
    How can I assign wifi just for access to the internet and Lan just for internal net work?
    By any chance is there any way to assign for example mail to get internet from wifi and the rest of the application use Lan for connection to internet ?

    not sure if I understand you correctly
    but many people use airplay mirror to mirror apps streaming movies and music from the Internet connection the device have
    be it from a internet connection the device is currently airplaying to is of no relevance
    but the device can't get data from both 3g and wifi at the same time
    not even a computer can do that, it use it's metric settings to only! get data from the fastests source

  • Statistics setup for 2LIS_11 and no storage space available internal table

    Hi, I am running statistical setup for 2LIS_11_VAITM. It ran for 10 hours and failed with an ABAP run time error. The error is "no storage space available for extending an internal table". For 11 application, the selection options is sales org, company code and sales document. We have tried twice, and already drilled down to the level of sales org and company code, but still with error.
    The only option is sales documents.
    The volume of the data is 16 million records around in VBAP table which needs to be in the setup table.
    What is the criteria to categorize the sales document.
    Can we use order types? We have 200 values in the order types. And I am not sure the document ranges in each order type is clearly defined and not overlapping each other, so that we could load those in the setup table.
    Please advise!! Or if you have other suggestions!
    Thanks!

    Hi
    It could be because of main memory problem... so Restrict your selections and do the statistical setup
    by the way how many comp codes you have? restrict with comp codes or doc ranges
    Thanks,

  • Can you use Airport for internet and Gigabit Ethernet for file sharing?

    i would like to complicate my network setup by using my Airport connection to the internet for internet access and then use the Gigabit Ethernet connection between my G5 tower and the MacBook Pro for file sharing, Compressor's distributed rendering, and possibly iTunes music/video sharing for Front Row.
    is this possible? could i just run a cat 6 cable between the two and network them together? or do i need to get a Gigabit Switch?
    i suppose i could just try running the cable between them and see what happens. i don't think these new machines require cross-over cables since the ethernet ports auto-detect that now, but is a cat 5e or cat 6 cable required for Gigabit speed?
    thanks,
    scott
    PowerMac G5 2.5GHz   Mac OS X (10.4.5)  

    Yes it would work. The Ethernet network would be used for local file transfers and the Airport for internet. However you will need to make sure Ethernet is at the top of the list of network ports in the Network Preferences.

  • Make Flash Plug-In for Firefox Remember Privacy Settings for Camera and Mic Access on Local File

    My company is using Flash Player to develop some kiosk-style applications to run on a standalone computer (no network connection). This computer will contain web pages containing Flash content. They will be opened from the local HD with Firefox with the Adobe Flash plug-in (v11.7.700.224). One of the applications accesses the microphone hooked up to the computer. When this application is started, it always asks for permission for "local" to access the microphone and camera. In previous versions of our system, we could click "Remember" if we did it once and that would make it so it wouldn't ask for permissions again (in this case, the Remember option isn't available, and the site settings don't even offer the Privace tab). However, in the previous case, we were running IE with a previous ActiveX Flash version (unfortunately, this approach is no longer available as we have had to switch to Windows 8 and that changes the game with IE and Flash entirely).
    At this point, we have tried to use the Global Settings for "Camera and Microphone Settings by Site..." to enter "Local" as an always allowed site. This does not seem to have any effect. We also tried entering the root directory of the applications in "Trusted Location Settings", but that also seemed to have no effect.
    I'm not sure what has fundamentally changed here. I think there might be some differences in the Plug-In version (compared to ActiveX), but I'm not sure what they might be or how to do the same thing as before.
    Any help would be appreciated. Thanks in advance.
    Torrey

    Chris,
    We learned that the Privacy tab (in Settings) can be found under the Flash plug-in for Firefox, but only if Firefox is running under an administrator.
    Unfortunately, we haven't had much luck with the mms.cfg file. The following was used in the mms.cfg file (placed in both the %WINDIR%\SysWow64\Macromed\Flash and %WINDIR%\System32\Macromed\Flash” directories):
    AVHardwareDisable = 0
    AVHardwareEnabledDomain = local
    AVHardwareEnabledDomain = 127.0.0.1
    AVHardwareEnabledDomain = localhost
    AutoUpdateDisable = 1
    The AVHardwareEnabledDomain settings seem to be getting ignored regardless of whether the user is a standard user or an administrator. I also checked to make sure it wasn't just a local problem by going to a website that uses a microphone (http://www.testden.com/accent-reduction/systemcheck.htm). Adding the requested domain to the list (AVHardwareEnabledDomain = train.act360.com) still didn't bypass the allow/deny dialog box.
    We know that the mms.cfg file is being read because setting "AVHardwareDisable = 1" will result in no prompt and that section being greyed out in Global Settings. I saw a post that suggested this setting was required to even make the AVHardwareEnabledDomain work, but it seems to block the local entirely and still brings up the dialog query on the internet site.
    Thanks,
    Torrey

  • Cisco ACS 4.2.1.15 for Windows and Network Access Profiles

    We are attempting to configure ACS 4.2.1.15 on Windows Server 2008 Member Server. Initially I only have the need to authenticate Network Admins for device administration and authenticate Windows AD groups using PEAP authentication. The general problem that I am having is that if I configure a Cisco 1200 Access Point  for PEAP and also setup The Access Point for Radius authentication pointed to the ACS server it always maps to the the first Network Access Profile and rather than it trying the second it will error sayiing some condition is not met depending on what changes I make. Can someone tell me what the criteria that is used to determine what NAP is used? According to the manual if all 4 criteria are not met then the Profile will not apply.
    I am using one ACS group that is mapped to an AD group for Wireless Access and a Second ACS group mapped to an AD group that includes the Net Admins. This group mapping appers to be working as the user group name seems to mapped correctly in the logs.  In short I have tried only configuring the Wireless NAP to only Allow EAP authentication using PEAP EAP-MSCHAPv2 and the Netadmins profile to include all protocols. Bascially what happens is if I have the Wireless NAP first it works fine for PEAP authentication on Wireless but if I try to administer the access point and provide credentials I get a message in the failed log that the authentication profile is not allowed in this Network Access Profile. Why does this not just go onto the next Network Access profile?
    I am familiar with version 3.2 but it does not seem to work the same.
    Any help would be appreciated on what I am missing.
    Thanks

    Hi Surenda,
                       Thanks for your reply. Nop, there is no WLC yet, but the WLC will be installed shortly.
    Thanks,
    Jean Paul

  • OWA for Iphone and international calling card

    Hello,
    I work as the Supervisor for a company that has just purchased many iphones.  The group that is in charge of email at my company will only allow "OWA for Iphone" to be used because in this way, nothing is downloaded to the device.  All email, calendar entries and contacts/people entries are web based.  Because nothing is downloaded to the device, the Iphone app for any international calling card company like Reliance or True Roots will not work.
    When I say, "will not work" this is why.  All international calling card companies apps that I have found, access the local downloaded contacts on the Iphone itself.  I have not found any that can connect to the people in the  "OWA for Iphone" app to make international calls for cheeper prices.
    Is there an international calling card company whose app will work with "OWA for Iphone" and not the locally stored contacts?  Or one that I can make the choice, choose the contacts from the local Iphone and or people in the "OWA for Iphone" app?

    International calling apps allow you to call an entry from your contact list.  When you make a call from your device using this International calling app it will hang up, dial a 1 800 or 1866 number, then redial the international number you dialed and complete the call.  This allows you to call for example, India for $.06/minute instead of $.50/minute or what ever your provider charges you.  It basically make it so your international calls go through your international calling app provider instead of your phone provider.  You still use your phone provider minutes, but the cost is rerouted to your international calling provider/partner.
    1. I know, its so hard to do anything.  Yes all smartphones (Iphones, Androids, Windows, etc...)  The email admins will not allow anything to directly download to the device from the company.  The OWA for IPhone app uses the web browser but changes the view of the email to look and feel user friendly.  Basically, OWA for Iphone is using the web to look at all email, contacts, and calendar entries.
    2. The international calling app (Reliance and all others I have found including Skype) will only look at local downloaded contacts.  Because we are using OWA for Iphone there are no downloaded contacts. So, the international calling app does not see the contacts to be able to call.
    If I go into OWA for IPhone and go to People and call somebody internationally +44 XX XXX XXXXX it works fine, but the international calling app does not activate becasue the app can't see the number.  This is because its looking only at the local downloaded contacts list, not the contacts on the web using OWA for Iphone

  • AE Setup for printer and Airtunes ONLY?

    If I set up a wireless network on my AE for printing and Airtunes, but my laptop accesses the internet via ethernet, does the AE allow access to that connection backwards through the laptop? (I don't want it to).

    dasharst, Welcome to the discussion area!
    Yes that is possible.
    If your Linksys is a wireless router, simply configure the AirPort Express (AX) to join the wireless network created by the Linksys.
    If your Linksys isn't wireless, simply connect the AX via Ethernet to one of the Linksys LAN ports. Configure the AX to act as a bridge (not sharing a single IP address).

  • Connecting to multiple Airport Express base stations for internet and TV?

    I want to be able to use wireless internet and stream music to my stereo at the same time, but I only have a single ethernet connection behind my stereo and it's connected to the Pay TV. My options seem to be an ethernet splitter (maybe - any ideas?), getting a new ethernet connection installed behind the stereo so I can insert this into the same Airport Express base station I use for my music, or buying a second Airport Express base station and connecting it to one of the other internet connections in the room, then connecting to both Airport Express base stations at the same time.
    Is this possible? Are there other alternatives?
    Many thanks

    Nate, Welcome to the discussion area!
    Once you have a network, you can connect multiple AirPort Express (AX) to that network (wirelessly or via Ethernet). When your computer joins that network it can access all the AX.
    You could take your current internet connection and run it into an inexpensive router with multiple Ethernet ports (not the AX). If this is a wireless router then your AXs could be located elsewhere and connect as wireless clients to that network. Once you computer joined that network it could stream music to the AXs.

Maybe you are looking for

  • Virus on Macbook Air

    If i take my computer to an apple store can they get rid of a possible virus? I am a freshman in college and some of the websites required to do my work required me to turn off my popup blockers. If you could help it would be greatly appreciated. Tha

  • I still haven't found an answer

    Why do i get this message when trying to 'authorize computer': E_AUTH_NOT_READY? Is there anyone out there who knows?

  • I need help with my adode flash player

    Why my adobe flash player isn't working

  • Standard HW question, what shall I buy?

    Two years ago I bought a new PC for Premiere Pro after I got a lot of very good advice here http://forums.adobe.com/message/3432674#3432674.  And that new system worked perfect, I never had any problem with a slow system so many THANKS to Harm, Chris

  • Business App Purchase Assigned to Personal Computer?

    How do I purchase an app for my business and put it on a specific employees computer (Macbook Pro) who has his own Apple ID without using a gift card scenario?