Re: [EMAIL PROTECTED] Different security based on network interface

2005-09-14 Thread Krist van Besien
On 9/14/05, Scott Gifford [EMAIL PROTECTED] wrote: AragonX [EMAIL PROTECTED] writes: [...] I know that mod_access and I think mod_security will allow me to do this but they do it based on IP address. I'm afraid someone will spoof the IP addresses of the internal network to bypass this

Re: [EMAIL PROTECTED] Different security based on network interface

2005-09-14 Thread AragonX
quote who=Scott Gifford AragonX [EMAIL PROTECTED] writes: [...] I know that mod_access and I think mod_security will allow me to do this but they do it based on IP address. I'm afraid someone will spoof the IP addresses of the internal network to bypass this security measure. The

RE: [EMAIL PROTECTED] Different security based on network interface

2005-09-13 Thread Administrator
This may be a stupid answer, but isn't it easily possible to set up the interfaces (or firewall, or both) so they reject source IP addresses in the wrong I/F? Or am I missing the point? David | On 9/13/05, AragonX [EMAIL PROTECTED] wrote: | Hello all, | | I am trying to secure my web server.

Re: [EMAIL PROTECTED] Different security based on network interface

2005-09-13 Thread Jean-Christophe Montigny
Hello, Administrator wrote: This may be a stupid answer, but isn't it easily possible to set up the interfaces (or firewall, or both) so they reject source IP addresses in the wrong I/F? Or am I missing the point? Just drop packets coming in the external interface that claim to have an IP

Re: [EMAIL PROTECTED] Different security based on network interface

2005-09-13 Thread Sean Conner
AragonX wrote: I'm afraid someone will spoof the IP addresses of the internal network to bypass this security measure. I don't see how that's possible. Given the following: M - malicious hacker at address M W - webserver I - internal network

Re: [EMAIL PROTECTED] Different security based on network interface

2005-09-13 Thread Scott Gifford
AragonX [EMAIL PROTECTED] writes: [...] I know that mod_access and I think mod_security will allow me to do this but they do it based on IP address. I'm afraid someone will spoof the IP addresses of the internal network to bypass this security measure. The easiest way to do this is with a