Firewall, Mail and File server solution



Similar documents
Small Business Server Part 2

Quick Scan Features Setup Guide

MCSE SYLLABUS. Exam : Managing and Maintaining a Microsoft Windows Server 2003:

MCSA Objectives. Exam : TS:Exchange Server 2007, Configuring

Quick Scan Features Setup Guide. Scan to Setup. See also: System Administration Guide: Contains details about setup.

Quick Start Guide Managing Your Domain

INSTALLATION AND CONFIGURATION GUIDE (THIS DOCUMENT RELATES TO MDAEMON v ONWARDS)

Mithi Connect Server deployment options

Configuring Outlook for IMAP. Creating a New IMAP Account. Modify an Existing Account

MICROSOFT CERTIFIED SYSTEMS ENGINEER Windows 2003 Track

Endian Unified Threat Management

Designing, Deploying and Managing a Network Solution for Small- and Medium-sized Businesses Course No. MS Days

Novell Open Workgroup Suite

AXIGEN Mail Server. Quick Installation and Configuration Guide. Product version: 6.1 Document version: 1.0

Exchange Outlook Profile/POP/IMAP/SMTP Setup Guide

CYAN SECURE WEB APPLIANCE. User interface manual

THE BCS PROFESSIONAL EXAMINATIONS BCS Level 6 Professional Graduate Diploma in IT. April 2009 EXAMINERS' REPORT. Network Information Systems

A host-based firewall can be used in addition to a network-based firewall to provide multiple layers of protection.

Exchange Outlook Profile/POP/IMAP/SMTP Setup Guide

Deploying BitDefender Client Security and BitDefender Windows Server Solutions

Guardian Digital Secure Mail Suite Quick Start Guide

602LAN SUITE 5.0 Groupware

Office 365 Migration Performance & Server Requirements

Hosted CanIt. Roaring Penguin Software Inc. 26 April 2011

How to Set-up Microsoft Outlook to Connect to your Arrowmail Exchange Mailbox

Emergic. A Complete Messaging & Security Suite A COMPLETE MESSAGING AND SECURITY SUITE

Implementing and Managing Microsoft Exchange Server 2003

PowerLink Bandwidth Aggregation Redundant WAN Link and VPN Fail-Over Solutions

Configuring your client to connect to your Exchange mailbox

Network Configuration Settings

Set up Outlook for your new student e mail with IMAP/POP3 settings

REST Professional Network Troubleshooting Guide

Small Enterprise Server Open Source Linux Based SES

Webmail. Setting up your account

Gateways Using MDaemon 6.0

Chapter 15: Advanced Networks

RAS Associates, Inc. Systems Development Proposal. Scott Klarman. March 15, 2009

TELSTRA BUSINESS MAIL QUICK REFERENCE GUIDE

MCSE Objectives. Exam : TS:Exchange Server 2007, Configuring

Web Hosting. CMS Development. Domain registrations. DNS Pointing. Website Publishing. SMB Starter Package. Static Website Development

Client configuration and migration Guide Setting up Thunderbird 3.1

ICANWK602A Plan, configure and test advanced server based security

המרכז ללימודי חוץ המכללה האקדמית ספיר. ד.נ חוף אשקלון טל' פקס בשיתוף עם מכללת הנגב ע"ש ספיר

EZblue BusinessServer The All - In - One Server For Your Home And Business

Advanced Mail Server Settings Options for Shared Hosting Clients

Millbeck Communications. Secure Remote Access Service. Internet VPN Access to N3. VPN Client Set Up Guide Version 6.0

BlackBerry Enterprise Server for Microsoft Office 365 preinstallation checklist

ALABAMA CENTRALIZED (ACE) PROJECT SUMMARY

Configuration Manual for Lime Domains

Microsoft Exchange Mailbox Software Setup Guide

INSTALLATION AND CONFIGURATION GUIDE (THIS DOCUMENT RELATES TO MDAEMON v9.5.0 ONWARDS)

StarterPlus Mailbox Software Setup Guide

VPOP3 Your post office Getting Started Guide

Microsoft Exchange Mailbox Software Setup Guide

What is included in the ATRC server support

Audience. At Course Completion. Prerequisites. Course Outline. Take This Training

Kerio Control. Step-by-Step Guide. Kerio Technologies

Phish Blocker: Spyware Blocker:

Using over FleetBroadband

Bulk ing Basics for Hilton Head Island Organizations

MailEnable Scalability White Paper Version 1.2

Configuring Your Gateman Server

Setting Up Scan to SMB on TaskALFA series MFP s.

1 Introduction to the Axxess Server

DESKTOP CLIENT CONFIGURATION GUIDE BUSINESS

Step-by-Step Configuration

Service Overview & Installation Guide

Delphi+ System Requirements

Workshop 5051A: Monitoring and Troubleshooting Microsoft Exchange Server 2007

Computer Networks 1 (Mạng Máy Tính 1) Lectured by: Dr. Phạm Trần Vũ MEng. Nguyễn CaoĐạt

Deploying BitDefender Client Security and BitDefender Windows Server Solutions

Advanced Diploma In Hardware, Networking & Server Configuration

1. Installation Overview

WineWeb Account Services

How To Set Up An Outlook Mailbox On A Windows 2007 (For Free) With A Free Account On A Blackberry Or Ipad (For A Free) Or Ipa (For An Ipa) With An Outlook 2007 (Free) Or

White Paper. Installation and Configuration of Fabasoft Folio IMAP Service. Fabasoft Folio 2015 Update Rollup 3

Course Syllabus. Implementing and Managing Microsoft Exchange Server Key Data. Audience. Prerequisites

Mail Services. Easy-to-manage Internet mail solutions featuring best-in-class open source technologies. Features

PavelComm s Pro-Tech Lite Fact Sheet

Reliable & Secure . Professional, Dependable, Complete Easy to Learn, Use and Grow

Introduction to Computer Security Benoit Donnet Academic Year

Technical Note. Configuring Outlook Web Access with Secure WebMail Proxy for eprism

OVERVIEW OF TYPICAL WINDOWS SERVER ROLES

Install and configure server

PineApp Archive-Secure Quick Installation Guide:

client configuration guide. Business

Configuring Security for SMTP Traffic

NETASQ MIGRATING FROM V8 TO V9

List of Common TCP/IP port numbers

redcoal SMS for MS Outlook and Lotus Notes

12/23/2013 LINUX AND I TECH SOLUTIONS. Linux mail server in Chennai surya

Agency Pre Migration Tasks

Quick Start Guide. Your New Account

How To Create A Mailbox In Windows Mail On A Pc Or Mac Or Ipad (For A Mac)

Optus SMS for MS Outlook and Lotus Notes

Library Computer and Network Security and Web Services

Virtual FAX Function in Vigor IPPBX 2820 Series

Product Overview and Functional Specification

Setup Guide for Exchange Server

Installation Overview

Transcription:

Firewall, Mail and File server solution

Table of Contents Introduction......2 Overview......3 Detailed description....4 Firewall......4 Other services offered by IPCop:......4 Mail and File Server......5 Mail services......5 File server......5 Backups......5 Introduction TruSoft Software offer a number of solutions aimed at: lowering bandwidth usage, providing stable, secure central file storage, providing central backup, low maintenance, low TCO Our solutions are based on GNU/Linux systems utilising open source software and have been proven to be effective. The Solution consists of two servers, one firewall/gateway/proxy that manages the ADSL internet connection and one mail/file server that can also be expanded to become a web server for internal web applications. Page 2 of 5

Overview The following diagram depicts the basic architecture and the services offered. Page 3 of 5

Detailed description Firewall The firewall is implemented using IPCop, a Linux-based secure multi-purpose firewall solution. Existing hardware can be used if the client have a PIII machine available, or we can supply a new entry-level machine. The client can also opt for a more powerful machine to allow the firewall to do on-the-fly checking for spam and viruses. The IPCop system is equipped with two network cards to effectively isolate the internal network from the Internet. IPCop routes traffic between the internal network and the Internet. The built-in intrusion detection system (Snort) and kernel-based firewall (iptables) monitors all traffic and effectively block unauthorised traffic from the Internet. IPCop can also be set up to prioritise certain traffic to ensure optimum usability. Other services offered by IPCop: Transparent Proxy The transparent proxy will cache HTTP data for a certain time, making access to frequently visited sites faster and use less bandwidth. No client-side setup required. DHCP Server The DHCP server will dynamically allocate IP addresses to computers on the internal network. The server can be set up to always allocate a certain address to a certain computer. Caching DNS DNS requests are cached by IPCop, so that frequently used addresses resolve faster. Time Server IPCop can act as a time server for internal computers to keep all computers in synchronisation. IPCop itself will again synchronise with international time servers VPN Server IPCop can be set up with Open VPN to be a secure VPN server. The network can then be accessed remotely via the Internet in a secure way. Each client needs it's own key and password. Port Forwarding IPCop can be configured to directly route all traffic on a certain port to an internal machine. This allows remote access only to one machine on the inside, improving security and control. Dynamic DNS A dynamic DNS service can be used to assign a domain name to the ADSL connection. This makes it easy to access the network via the Internet for administration. Web interface The easy to use, secure web interface makes administration and monitoring of IPCop easy and can be done from any internal PC. No screen, monitor or mouse is required for the IPCop server. Plug-ins Additional plug-ins exist that extend the functionality of IPCop. Page 4 of 5

Mail and File Server The Mail and File Server is based on Novell OpenSUSE Linux. The server runs the Postfix mail server with Courier IMAP/POP3 server and fetchmail to collect mail. SAMBA is be used to share directories via SMB to Windows clients. A custom backup system allows for automatic backup of files to external USB drives. Mail services The server hosts a mailbox for each internal email address. The mailboxes are available via IMAP/POP3. The server will periodically read each user's mail from the ISP's mail server and drop mail into the local mailboxes after it has been scanned for viruses and spam. Viruses will be quarantined and messages suspected of being SPAM can be marked as SPAM or rejected directly. Users will then read the mail from the local mailboxes via IMAP or POP3 using any IMAP/POP3 capable email client (Mozilla Thunderbird, Microsoft Outlook, etc) on the workstations. When a user send an email, the email client will deliver the mail to the local SMTP server running on the Mail/File server. The SMTP server will then determine if the mail is destined for an internal user or external user. If the mail is addressed to an internal user (@your_domain) then the mail be delivered directly to the user's mailbox on the server. The mail will not be passed on via the Internet to the ISP's mail server. If the mail is addressed to an external address, then the mail server will pass it on to the ISP's SMTP server for delivery. This means that mail that employees send to each other will not be sent out over the ADSL connection, and read back again, saving bandwidth, making delivery faster and enabling larger attachments to be sent. It is also possible to install an open source groupware server like Hula, Kolab, Zimbra, etc. This will give similar functionality as a Microsoft Exchange system. (Shared address book, shared calendaring, shared folders in Outlook) File server The file server functionality is implemented using SAMBA. SAMBA is an open source implementation of the SMB protocol that is used by Windows systems to share folders. The server will have shared folders available that can be mapped as shared drives on Windows workstations. User and group access can be implemented to only allow certain users access to certain files and folders. The server can also be configured to act as an authentication server for Windows 2000/XP/2003 Professional clients. Backups TruSoft Software have developed a custom backup solution that will automatically backup selected directories to an external USB disk as soon as the disk is connected to the server. No human intervention is required. When the backup is done, the server will beep to signify that the disk can be disconnected again. Normally all email on the server, server configuration files and all shared SAMBA directories are backed up, but additional directories can also be added. TruSoft Software also offer a service to backup the data via the Internet to an off-site server via a secure protocal. The backup is done every night, or as often as the client requires. Page 5 of 5