LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

Re: Advice on security: Servers at port 80 or LVS-DR redirect 80 to 8080

To: "LinuxVirtualServer.org users mailing list." <lvs-users@xxxxxxxxxxxxxxxxxxxxxx>
Subject: Re: Advice on security: Servers at port 80 or LVS-DR redirect 80 to 8080?
From: Horms <horms@xxxxxxxxxxxx>
Date: Fri, 14 Mar 2003 20:43:39 +0900
On Tue, Mar 11, 2003 at 06:25:30PM -0000, jpcl@xxxxxxxxxxxxxx wrote:
> Im' in the process of setting up a JBoss cluster using LVS-DR as the
> frontend.
> 
> The LVS is performing great and now we are in some details like getting
> everything to run at the standart web port 80 instead of the standart
> JBoss port 8080.
> 
> So I'm wondering if there is any difference (in performance or security)
> about these alternatives, that may inluence the decision:
> 
> * Solving at realserver level
> a) Getting my servers to port 80
> b) Redirecting my server port 80 to 8080
> 
> * Solving at director level
> c) Balance port 80 and then redirect outgoing 80 to 8080
> d) Redirecting port 80 to port 8080, and then balance.
> 
> I don't like a) for the following reason: Besides having to be root to run
> at port 80 (here they actually don't care about that anyway), every time
> we upgrade a server to a new version it's one more config file to
> change... times the number of servers!

a) is probably the easiest and in my opinion the best because
   it makes for the simplest setup.

The rest of the options are really much of a muchness, though
I am not entirely convinced that c) will work.

-- 
Horms
<Prev in Thread] Current Thread [Next in Thread>