dmz server setup - opinions
From: Jeff (jeff.dyke_at_gmail.com)
Date: 07/31/05
- Previous message: Giorgos Keramidas: "Re: C program to write to the com port"
- Next in thread: Chuck Swiger: "Re: dmz server setup - opinions"
- Reply: Chuck Swiger: "Re: dmz server setup - opinions"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Date: Sun, 31 Jul 2005 11:18:28 -0400 To: questions@freebsd.org
I realize this may be partial religion and then potentially bias due to the list
but here goes anyway.
I need to build a DMZ server, of sorts, that will sit on the public internet.
It will take in data from embeded devices and in turn services from behind a
firewall will pull data from it to later process. The main processes that i
need to run are ftpd,httpd, possibly smtpd(sasl2,tls), and later proprietary
code that talks to the embeded devices.
Originally i was thinking of using OpenBSD, as it seems to lend itself very
nicely to the public but secure environment. On the other hand, if i were to
use FreeBSD, i could jail each process, granted i could also chroot each process
in OpenBSD and httpd is already done for me.
I will be running a firewall on the box either way and will also have sshd and
rsyncd running, only allowing access from the internal network.
I have move expierence with freebsd, but my limited knowlegdge based on an
install and configuration of openbsd3.7 has made me comfortable with it as well.
Any opinions on which OS is better suited for the task? Security and reliablity
are the foremost concers( aren't they everyones ) and i think both OS are more
then up to the task.
Thanks for any input.
jeff
_______________________________________________
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscribe@freebsd.org"
- Previous message: Giorgos Keramidas: "Re: C program to write to the com port"
- Next in thread: Chuck Swiger: "Re: dmz server setup - opinions"
- Reply: Chuck Swiger: "Re: dmz server setup - opinions"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Relevant Pages
- Re: RX (download) limit problem
... > I've been seeing a strange problem with my 5.4-STABLE freebsd ... >
behind it or the firewall itself) can get a decent rate. ... > In talking to some openBSD
guys we had a theory that it might be something ... > the upload and download being
kept symmetric and hence so low on the ... (freebsd-current) - Dear god not another *BSD debate (was - hiding OS name)
... > JSA> Just because the firewall is OpenBSD do NOT ... >
JSA> well tuned and hardened FreeBSD box. ... (FreeBSD-Security) - Re: dmz server setup - opinions
... >> I realize this may be partial religion and then potentially bias due ...
>> services from behind a firewall will pull data from it to later ... >> if
i were to use FreeBSD, i could jail each process, granted i could ... >> also chroot
each process in OpenBSD and httpd is already done for me. ... (freebsd-questions) - Re[2]: : hiding OS name
... JSA> well tuned and hardened FreeBSD box. ... OpenBSD had earned
it reputation on security. ... for a firewall and FreeBSD would be the best choice of any
other intel ... (FreeBSD-Security) - Re: solaris
... >> router while I attempted to explain the router was ... >> of
handling a CLI OS like FreeBSD? ... that these individuals would not be the target market
... > despite the fact that it should include a firewall. ... (freebsd-questions)