Secondary IP?

Discussion in 'Apache' started by subnet_rx, Mar 25, 2008.

  1. #1
    Can anyone tell me what they mean by this?


     
    subnet_rx, Mar 25, 2008 IP
  2. worldpresident

    worldpresident Banned

    Messages:
    163
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    0
    #2
    this means that they protect you for hacker attacks and they allocated only 1 ip for your server..

    you don-t have a secondary ip...
     
    worldpresident, Mar 25, 2008 IP
  3. subnet_rx

    subnet_rx Well-Known Member

    Messages:
    141
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    138
    #3
    They will give me more, but I'm just not sure I understand why I'd want more for services.
     
    subnet_rx, Mar 25, 2008 IP
  4. SSANZ

    SSANZ Peon

    Messages:
    861
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    0
    #4
    you don't know what your talking about.



    Servers are assigned multiple IP addresses for reason(s);

    Multiple DNS servers ( Yes, each production hosting server has two nameservers, each one requires a seperate IP )
    Multiple sites - Sites using SSL certificates require an IP.
    mail - suggested to have a seperate IP assigned to mail server.

    If you have 1-100 IP's it isn't going to stop a " hacker attack ". As he quoted above basically - " IF ALL SITES ARE PUT ONTO ONE IP, IF THAT ONE IP IS FLOODED ALL SITES GO DOWN ". However, most attacks are big enough to take down the whole box, not just one IP.

    dDOS attacks usually target multiple IP ranges assigned to one box afaik.
     
    SSANZ, Mar 25, 2008 IP
  5. subnet_rx

    subnet_rx Well-Known Member

    Messages:
    141
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    138
    #5
    Yeah, it will be one box, so when they talk about using different ip's for services, they are talking about DNS and mail? I thought maybe they were talking about setting up different ip's for ftp, ssh, http, etc.
     
    subnet_rx, Mar 26, 2008 IP
  6. worldpresident

    worldpresident Banned

    Messages:
    163
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    0
    #6
    sites requires only 1 ip...the ports are diffrent for mail, http, ftp..etc
    25/80/21

    ussualy they assign 2 ip-s(2 dns-s)...in case that 1 server goes down..the other take control............ DNS-S..ex:n1.domain.com....in back of it is a simple ip.............

    offcourse you can assign 100 ips for your site, 1 ip for each application.........
     
    worldpresident, Mar 26, 2008 IP
  7. scamp81

    scamp81 Peon

    Messages:
    25
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #7
    Having multiple ips really won't help you get into your server if it's attacked or compromised unless, maybe, if they are on different NICs. I wouldn't worry about using the same public IP for both web and management if it was me. Just make sure you have the management ports locked down to your IP address.
     
    scamp81, Mar 26, 2008 IP
  8. Ladadadada

    Ladadadada Peon

    Messages:
    382
    Likes Received:
    36
    Best Answers:
    0
    Trophy Points:
    0
    #8
    To go even further, it's hard to imagine an attack that could bring down the NIC or the switch or flood the upstream bandwidth but leave the computer itself still working.

    Where I work we have two ways of accessing the boxes: one is through an internal IP address (10.0.0.0/8 or 192.168.0.0/24) the other is through a console server which ties in to the console port on the back of the machine. None of the machines actually have external facing IP addresses but that's really only useful if you have multiple machines and are load-balancing them. I can still get access to the console even if I mess up the firewall and lock myself out or if the NIC short circuits and dies completely.

    The scenario for an attack would probably be something like reaching the maximum number of allowed connections meaning that you couldn't use ssh to connect to the box. Having a second IP address wouldn't help you in this situation anyway.
    The two most likely DDoS attacks (I imagine) would be saturating upstream bandwidth and maxxing out the CPU usage on your box. Again, having a second IP address won't help you with either of those problems.

    There are plenty of good reasons for wanting multiple IP addresses but I have yet to see a valid way of accessing your box with a second IP address that wouldn't work with just the one.
     
    Ladadadada, Mar 27, 2008 IP