Mast Kalandar

bandar's colander of random jamun aur aam

Mon, 22 Aug 2005

< Re-organisation of IMSc Network Topology | · | DNS and e-mail, and how ERNET went its own way >

Proposal for new network toplogy


ccm, imsc, sysadmin [link] [comments ()] [raw]

The proposed network has three parts (each part could have sub-parts).

  1. Internet zone. This consists of machines connected directly to the internet with only the router in between. The router should have access rules to ensure that local IP addresses are really local! This zone contains the DNS slave servers, Mail exchangers, Web accelerator.

  2. The Server Zone. This zone which consists of primary servers for the domain. DNS primary server, Mail spool, "Real" Web server(s). We also have the NFS/NIS servers and clients.

  3. The Client Zone. This zone which consists of the clients for the internet and the intranet (server zone).

  4. The authentication gateway. This machine serves multiple purposes and needs careful configuration. It is connected to all three zones.
    1. It decides what connections are permitted from the client zone to the intranet and the internet.
    2. It decides what connections are permitted from the internet zone to the intranet. Only "RELATED,ESTABLISHED" are usually permitted!
    3. It decides what connections are permitted from the internet to the client zone. Again usually only "RELATED,ESTABLISHED".
    4. It may grant additional access if the machine making the connection is "authenticated" in some way (SSH,SSL,...).

Archives

< August 2005 >
SuMoTuWeThFrSa
  1 2 3 4 5 6
7 8 910111213
14151617181920
21222324252627
28293031   

2016, 2015, 2014, 2013, 2012, 2011, 2010, 2009, 2008, 2007, 2006, 2005, 2004, 2003, 2002, 2001, 2000, 1999, 1997, 1995,