Keresés

Új hozzászólás Aktív témák

  • n00n

    őstag

    válasz Bjørgersson #20508 üzenetére

    Inkább ideírom amikben nem vagyok biztos :)

    Own Network:
    We need to create a separate one to isolate us from other companies
    It's more secure
    All our servers will be in this network

    Firewall Rules:
    It's completely different, than on xxx (előző cég)
    There are two interfaces
    An internal and an external one (eth0, eth1)
    You can edit the internal on the server, the external on the web interface
    We need about 5-10 firewall rules only
    On XXX we needed to configure the firewall on every machine.

    Example Rule:
    We can connect from anywhere on the 22 port to every server, which has the „server” tag

    VPN:
    We need a VPN server here as well
    This allows us to communicate with the servers on the internal addresses
    Need to enable masquerade in the VPN server's firewall (firewalld). It forwards the necessary IP addresses to the internal network
    We will need two VPN accounts in the transitional period

    New company:
    YYY doesn't allow the username/password authentication, we need SSH keys
    It's more secure, but we need a policy for this
    You can create SSH key for just one server
    Or you can add a key for all
    Every user has a Linux user (sudo)

    Köszönöm. :)

Új hozzászólás Aktív témák