Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Support
  3. Subnet

Subnet

Scheduled Pinned Locked Moved Solved Support
networking
12 Posts 5 Posters 2.1k Views 5 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • robiR Offline
    robiR Offline
    robi
    wrote on last edited by
    #3

    You may also wish to set up IP aliases on the Cloudron IP interface ex: eth0:[0-3], so all IPs go there.

    Conscious tech

    1 Reply Last reply
    0
    • girishG Offline
      girishG Offline
      girish
      Staff
      wrote on last edited by
      #4

      As @subven said, the code currently handles only one IPv4/IPv6 address. I would also be interested in knowing why you would want to assign multiple IPs though to the server.

      K 1 Reply Last reply
      0
      • girishG girish

        As @subven said, the code currently handles only one IPv4/IPv6 address. I would also be interested in knowing why you would want to assign multiple IPs though to the server.

        K Offline
        K Offline
        krumel
        wrote on last edited by
        #5

        @girish
        I am not OP, but wouldn't that be useful to provide some Apps to an internal network and some for an external network only?

        girishG 1 Reply Last reply
        0
        • K krumel

          @girish
          I am not OP, but wouldn't that be useful to provide some Apps to an internal network and some for an external network only?

          girishG Offline
          girishG Offline
          girish
          Staff
          wrote on last edited by
          #6

          @krumel Indeed, that would be possible if the server has NICs - one internal and one external. Is this setup common in practice?

          K subvenS 2 Replies Last reply
          1
          • girishG girish

            @krumel Indeed, that would be possible if the server has NICs - one internal and one external. Is this setup common in practice?

            K Offline
            K Offline
            krumel
            wrote on last edited by
            #7

            @girish
            Well, especially in setups where Cloudron is on a VM I recon it is somewhat common - just from Reddit alone I know quite a few people who use a similar setup to mine:

            Personally my instance is on a Proxmox host in a DMZ,we have separate networks for purely internal services and for non-cloudron external services (and a purely management network as well). For some services we use MacVLAN on docker to provide separate IPs for containers.
            While this absolutely could be achieved with VLANs as well, in a Proxmox environment it was easier to use "physically" separate networks and route them properly through an OPN Sense VM.

            In theory one surely could use two Cloudron instances, but that would first be quite expensive, but also limit some backend functionality imho.

            Kind regards,
            Phil

            1 Reply Last reply
            1
            • girishG girish

              @krumel Indeed, that would be possible if the server has NICs - one internal and one external. Is this setup common in practice?

              subvenS Offline
              subvenS Offline
              subven
              wrote on last edited by
              #8

              In the "common" scenario you maintain an network internal DNS server that routes traffic for some requests or (sub)domains to internal resources for security, development or testing purposes. Similiar to what you could do with your hosts file but at network level where sometimes resources are only accessible via VPN. Every request that is not served by the internal DNS will be forwarded to the external (real) DNS server that is in charge of the domain.

              There are some cases where you separate traffic with NICs (like for management interfaces) but in case of Cloudron this could already be solved by unbound. Most use cases are solveable this way and there is already documentation present.

              Lets say you don't want to expose the dashboard to the public. You can block the routing to my.domain.com (or wherever your dashboard is at) with your network or VPS providers firewall for sure. In some cases you will lose access as well and other services can be affected so maaaaybe it could help to seperate services to different NICs....but personally I'm fine with the way Cloudron works.

              K 1 Reply Last reply
              1
              • subvenS subven

                In the "common" scenario you maintain an network internal DNS server that routes traffic for some requests or (sub)domains to internal resources for security, development or testing purposes. Similiar to what you could do with your hosts file but at network level where sometimes resources are only accessible via VPN. Every request that is not served by the internal DNS will be forwarded to the external (real) DNS server that is in charge of the domain.

                There are some cases where you separate traffic with NICs (like for management interfaces) but in case of Cloudron this could already be solved by unbound. Most use cases are solveable this way and there is already documentation present.

                Lets say you don't want to expose the dashboard to the public. You can block the routing to my.domain.com (or wherever your dashboard is at) with your network or VPS providers firewall for sure. In some cases you will lose access as well and other services can be affected so maaaaybe it could help to seperate services to different NICs....but personally I'm fine with the way Cloudron works.

                K Offline
                K Offline
                krumel
                wrote on last edited by
                #9

                @subven
                Security wise that is a quite limited scenario.
                This would mean that internal clients would need external access for services that are both internal and external- a scenario that is often undesired.
                DNS is never a security measure.

                1 Reply Last reply
                0
                • girishG Offline
                  girishG Offline
                  girish
                  Staff
                  wrote on last edited by
                  #10

                  @krumel Can you make a feature request post? Can look into this.

                  K 1 Reply Last reply
                  1
                  • K krumel referenced this topic on
                  • girishG girish

                    @krumel Can you make a feature request post? Can look into this.

                    K Offline
                    K Offline
                    krumel
                    wrote on last edited by
                    #11

                    @girish
                    As requested:
                    https://forum.cloudron.io/topic/7839/more-than-1-network-nic-bind-container-to-networks/1

                    girishG 1 Reply Last reply
                    1
                    • K krumel

                      @girish
                      As requested:
                      https://forum.cloudron.io/topic/7839/more-than-1-network-nic-bind-container-to-networks/1

                      girishG Offline
                      girishG Offline
                      girish
                      Staff
                      wrote on last edited by
                      #12

                      @krumel thanks!

                      1 Reply Last reply
                      0
                      • girishG girish marked this topic as a question on
                      • girishG girish has marked this topic as solved on
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Don't have an account? Register

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • Bookmarks
                      • Search