Build-Example for small OMV with web-connection?

  • Heyho Guys!


    I need some advice. My HP N40L is storing all my personal things and - because of that - not connected to the web.
    But occasionally I need more than I can get from my hosted HiDrive. I want my own FTP-Server, connected via dyndns to the web. And maybe later more.


    So I need hardware-suggestions. Cheap, neither under- or overpowerd. Any ideas?


    Thanks!

  • I would guess another HP N40L would work, though I would be much more concerned about security of the LAN and all the computers attached. Because if a bot or something broke into the FTP server connected to the net they could conceivably gain access to all of the machines on the LAN through what is known as island hopping.


    Take a look at this. While it talks about protecting the parents from the kids, think of the kids as the ftp server. The set up is involved and in particular how to get the parents/main LAN side to talk to the kids/ftp side. Security is no simple thing.

  • Just as a sidenote: dyndns is no longer free. noip offers similar services for free (for the time being, at last). And there are many other free dynamic dns services available, still.


    If you are concerned about security, don't use FTP, but run a SSH/SCP server. You can transfer files just like over FTP, but SSH is much more secure. Plus you can use certificates and keyfiles for authentication instead of passwords.
    Plus there is a technique called "chroot jail" that will only allow access to certain files/folders through SSH. This way even if the account is compromised, the whole server isn't (at least when done correctly... ;) )

  • hi fizze,


    the last time I checked the chroot jail under debian wasn't secure at all.
    Did this change lately?


    Greetings
    David


    PS: A friend recommend chroot years ago to me. I could break out with a simple cd, but we could never solve where the problem was...

    "Well... lately this forum has become support for everything except omv" [...] "And is like someone is banning Google from their browsers"


    Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.

    Upload Logfile via WebGUI/CLI
    #openmediavault on freenode IRC | German & English | GMT+1
    Absolutely no Support via PM!

  • Well, I don't know which shell we used but we tried to chroot some program or daemon (not ftp in particular, but I know proftpd uses chroot too). I think it wasn't bash but some more simple shell, but I could just cd /etc/ or so to get into the real environment.


    Greetings
    David

    "Well... lately this forum has become support for everything except omv" [...] "And is like someone is banning Google from their browsers"


    Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.

    Upload Logfile via WebGUI/CLI
    #openmediavault on freenode IRC | German & English | GMT+1
    Absolutely no Support via PM!

  • Hmmm, no hardware-suggestions... :cry: The N40L is to huge...


    Security should not be a huge problem. This tiny machine is shoud be an upload-machine for images, when I'm on vacations. So all other PCs would be disconnected from the powercord...
    DynDNS is a synonym. I'm using one from my hosting-package.

    • Offizieller Beitrag

    Use a mini-itx board in a small case.

    omv 7.0.5-1 sandworm | 64 bit | 6.8 proxmox kernel

    plugins :: omvextrasorg 7.0 | kvm 7.0.13 | compose 7.1.4 | k8s 7.1.0-3 | cputemp 7.0.1 | mergerfs 7.0.4


    omv-extras.org plugins source code and issue tracker - github - changelogs


    Please try ctrl-shift-R and read this before posting a question.

    Please put your OMV system details in your signature.
    Please don't PM for support... Too many PMs!

  • bitfenix Prodigy
    bitfenix Prodigy M


    Greetings
    David

    "Well... lately this forum has become support for everything except omv" [...] "And is like someone is banning Google from their browsers"


    Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.

    Upload Logfile via WebGUI/CLI
    #openmediavault on freenode IRC | German & English | GMT+1
    Absolutely no Support via PM!

    • Offizieller Beitrag

    There is a good selection of cases here. I used one of these a while back. Any mini-itx motherboard would work. You can get just about any processor on a mini-itx board. So, pick one with the right power for your needs.

    omv 7.0.5-1 sandworm | 64 bit | 6.8 proxmox kernel

    plugins :: omvextrasorg 7.0 | kvm 7.0.13 | compose 7.1.4 | k8s 7.1.0-3 | cputemp 7.0.1 | mergerfs 7.0.4


    omv-extras.org plugins source code and issue tracker - github - changelogs


    Please try ctrl-shift-R and read this before posting a question.

    Please put your OMV system details in your signature.
    Please don't PM for support... Too many PMs!

  • Yeah, a mini-ITX with a low power consuming CPU like the Asus M45 I use in my home NAS, passively cooled. The Bitfenix Prodigy is a very good case, but a little over-powered for a small NAS with the given requirements. A small case like these Rye suggested will do it. If you can put your hands on two 2,5" disks, use them. A small one for the OS and a bigger one for the data, these disks do not get too hot and they consume less power than a 3,5" one.


    I just don't know if it is possible to run vsftpd on a OMV box, but if it is possible I would use it. For my employer I have build a virtualized FTP server running on Fedora using vsftpd with virtual users only, all jailed in their own root. They do not have a shell and the OS does not know about them. IMHO one of the securest ways.

    Homebox: Bitfenix Prodigy Case, ASUS E45M1-I DELUXE ITX, 8GB RAM, 5x 4TB HGST Raid-5 Data, 1x 320GB 2,5" WD Bootdrive via eSATA from the backside
    Companybox 1: Standard Midi-Tower, Intel S3420 MoBo, Xeon 3450 CPU, 16GB RAM, 5x 2TB Seagate Data, 1x 80GB Samsung Bootdrive - testing for iSCSI to ESXi-Hosts
    Companybox 2: 19" Rackservercase 4HE, Intel S975XBX2 MoBo, C2D@2200MHz, 8GB RAM, HP P212 Raidcontroller, 4x 1TB WD Raid-0 Data, 80GB Samsung Bootdrive, Intel 1000Pro DualPort (Bonded in a VLAN) - Temp-NFS-storage for ESXi-Hosts

  • A case smaller than the N40L is going to be hard to find, as the Prodigy is bigger and this Cooler Master is probably close to the same size.

Jetzt mitmachen!

Sie haben noch kein Benutzerkonto auf unserer Seite? Registrieren Sie sich kostenlos und nehmen Sie an unserer Community teil!