Should iChain Proxy Server Have 3 NIC cards?
Novell Cool Solutions: Question & Answer
Q:
What is the reasoning behind the statement in the iChain documentation that the iChain proxy server should have 3 NIC cards?
A:
The third interface is recommended when you are using the iChain wizard / FTP to the iChain proxy server. As this is insecure communication the administrator could communicate directly with the port (cross over cable) or on a separate network defined by the third interface.
Most customers will need to have at least two nic's. One for the private and one for the public. iChain is used for security. If you use one nic card that means that the end user has direct access to the web server. This would allow a security hole because someone could hack directly into the web server especially if the web server doens't control access. But most configuration will not have the web server on the public side.
The third NIC card would be for security purposes during configuration. When configuring iChain using ConsoleOne or the browser based admin gui everything is passed over clear text so any configurations can be sniffed and exploited. You can enable configuration from any interface but to prevent any security holes it is best to do all of the configuration on an isolated interface.
Novell Cool Solutions (corporate web communities) are produced by WebWise Solutions. www.webwiseone.com
