I was up early this morning to finish my long outstanding project to setup a new firewall server. The server has been (mostly) ready for a while now but I've been putting off finishing the job, because I knew the final setup would require a lot messy configuration changes on all the computers on my network.
As I expected it took a few hours to get back to normal Internet access after all the minor details were cleared away. But it all works now and I'm happy with the results. I'm sure it is my imagination but web pages seem to be loading a little faster with the new firewall. The new server is slightly faster but I doubt that it would make a noticeable difference.
There is one remaining issue: IPv6. The first problem was the version of Shorewall in Debian Lenny/stable does not support IPv6, but I found a back port of the newer Shorewall on the package maintainers web site, so that obstacle has been cleared. I've never set up an IPv6 network before, so I'm sure there will be other head scratching moments.
Showing posts with label network. Show all posts
Showing posts with label network. Show all posts
Saturday, October 3, 2009
Tuesday, December 2, 2008
Relaxing Day
After the hectic pace of last week it was good to slow down a little. I did some planning for another Linux server installation but did not push myself to actually get started. I also looked at my own network plans which have been stalled for some time now. My main server is a little overloaded with too many functions. It runs Postfix, Apache, BIND (for internal use only), several lesser services, and the firewall. In addition, the server started life as my desktop system and has never been reinstalled so it has accumulated some cruft over the years. It has been running the same Debian sid install for exactly 10 years, dutifully updated on a daily basis.
I'd really like to split up the server functions. For one thing, it will give a chance to configure things better from the start. For another, it will remove the eggs from the same basket. For example, I need a master DNS server for my own domains but I would prefer to have the DNS on a separate system in case BIND is comprised. I'm not sure how far to go with separating the services since more hardware requires more space, makes more noise, and of course uses more electricity. Since I will likely be using old PIIs and PIIIs, they do not have the performance to run virtual servers. Why use such old systems? Because I can get them for free.
I'd really like to split up the server functions. For one thing, it will give a chance to configure things better from the start. For another, it will remove the eggs from the same basket. For example, I need a master DNS server for my own domains but I would prefer to have the DNS on a separate system in case BIND is comprised. I'm not sure how far to go with separating the services since more hardware requires more space, makes more noise, and of course uses more electricity. Since I will likely be using old PIIs and PIIIs, they do not have the performance to run virtual servers. Why use such old systems? Because I can get them for free.
Subscribe to:
Posts (Atom)
