[KLUG Members] http switching?

Peter Buxton members@kalamazoolinux.org
Mon, 27 Aug 2001 22:25:53 -0400


On Mon, Aug 27, 2001 at 09:11:51PM -0400, Bruce Smith was only 
   escaped alone to tell thee:

> If you must run _internal_ services on it like squid, make sure you 
> block access to all of it's ports from the internet side.  Even with
> the ports blocked, it's still not a good idea.

Yeah, squid would be just an internal service. :( I really don't feel happy
about bloating their servers from one to three (main, squid, firewall). I
should probably set up squid on that Cyrix machine and see how much of a
load squid imposes. I'm not really sure how much web surfing anyone there
does, if it comes to that.

Currently, there is no firewall. (I inherited this situation!) The ISDN
adapter uses NAT, so any incoming call not for ssh or smtp and otherwise not
requested gets bounced. Hmm... I wonder if SNMP on the adapter could tell me
how much port 80 traffic we're moving? Hm....

Thanks!