Friday, March 14, 2008

Running Your Own Web Server

This article will cover the basics about running your own web server out of your home. However, before I provide some direction on how to go about doing this I am going to give you the "pain points". I am also going to give you some reasons why running your own web server might not be for you.

Why you don't want to run your own web server?

If you are looking to sell something online you should look at a business web hosting solution. Two reasons. One, you are not going to be able to harden your server enough to make it secure for conducting business transactions. Second, you need to ensure that your site is available to your customers 24/7/365 or as close to 100% uptime as you can get. With web hosting you can typically get 99% uptime. You are very unlikely to come close to this trying to run your own server. Your uptime will be based on the uptime of your internet service provider. Plus every time you update Windows you will likely need to reboot your machine. And, are you familiar with...

- How to setup and configure a router?
- The difference between a physical and a software firewall?
- Do you know how to setup, configure, and secure a web server?
- Do you know enough about networking to run and maintain a server?

It is certainly within the realm of a fairly technically savvy person to setup and administer their own web server on the internet, but it takes some work, and any claims that it is easy to do should be met with guarded skepticism. This advice is coming to you from someone that ran their own web server on the internet for almost two years.

On the other hand it is pretty easy to (relatively speaking) setup and run a web server against your localhost (127.0.0.1) address. This web server will only be available to you local PC, but can serve as the test platform for your web site.

Some direction on running your own web server

Well, if you have read the last section and are still reading then you are looking for some direction. I am going to be offering information from the perspective that you are somewhat familiar already with the terms I am throwing about. The links I have provided here will go into more detail. Again, setting up and maintaining your own web server is not easy and requires a broad range of technical knowledge.

I will be showing you how to setup the Apache web server on your PC running under Windows. I am running Windows XP - Professional. You can run a web server using Windows XP - Home or Windows 2000. I mention this as any specific guidance I am giving you might vary if you are using something other than XP Professional. Also, I have not tried doing this on any other version of Windows.

Getting the software

You can go directly to Apache and get the webserver. But, what if you want to add blog software, forum software, Php, and other packages that do not come standard with the web server itself? Like I said this stuff is not easy. But wait, I am about to turn you on to one of the most comprehensive web packages available. This web package could probably be installed by your Grandmother without difficulty! All you need to do is download the file (it is a huge 186mb file). Once you download it installation is so simple it is ridiculous. The folks that did this are just brilliant. Most software shops could take a lesson from them in installation and configuration management.

This software comes bundled with blog software, forum software, MySQL database, apache security module and much more. The price is right as well. This site is not really easy to find in the search engines which goes to show that sometimes some of the best stuff on the web is buried quite deep. The url is http://www.devside.net/

Figuring out if IIS (Internet Information Server) is enabled?

I am assuming that you are going to install and use Apache as your web server. As such you need to see if IIS is running on your machine as there might be a port conflict as port 80 is the default port.

Some misc. advice (You may likely need to do a bit more digging to deal with the advice given here.)

Setting up your router

- DO NOT open up your entire DMZ to the internet are you will be toast!!!
- Only open up port 80 and port 23 (if you plan on letting people download stuff using FTP. Note, they can download files using http which runs on port 80).

Port Forwarding
- Find a service like ZoneEdit. This is what I use. It is free for low to medium traffic sites.

Your ISP

- Some ISP's block port 80. You can still run your webserver, but it will have to be done on another port (81, 82, etc...)
- Some ISP's have policies that do not allow their customers to run websites. You should read your internet service agreement for details.

For another decent link to a site with good information on setting up a web server go to http://www.diywebserver.com/


Eric Matthews is the owner of http://www.anglesanddangles.com which provides information on web development covering technologies like PHP, Html, Perl CGI, as well as other resources to assist you with your website.

Labels: , , , ,

Monday, March 10, 2008

Monitor the Uptime of Your Websites and Servers. Downtime is Expensive!

There are companies, which websites are essential for their business success, as they are generating the most or the whole of the company?s revenue. Maybe also you belong to them. When this kind of website (server) is down, your business is affected. If your website is hosted by another company, you probably have some sort of ?uptime? guarantee. Nevertheless, what exactly is uptime and how do you measure it. The basic definition of uptime is the period of time when your site is up and running, being accessible and able to satisfy customers.

The opposite, when your site is not accessible, it is down. And that is how you measure downtime. Faulty routers, malfunctioning LANs, or a loss of electrical power typically causes most of the downtimes; only rarely are caused by a natural disaster. Most often, it is caused by failures from the telecommunications company or an application failure, not a fire, flood or other catastrophe.

The cost of downtime calculation of course depends on many factors, like the products and services you provide, the size of your company, the number of online sales, etc. Even if you do not sell any products or services online, there is still a cost of downtime, but then in terms of damage of reputation etc. Calculate the cost of downtime is difficult and varies from one company to another. There is no ?average business?, so the statistics that quantify the cost of downtime for average businesses are not helpful.

The cost of downtime include direct costs such as the labor charges for a team of technologists who had to resolve the outages. The indirect costs are much more difficult to calculate and include potential lost revenue, reductions in worker productivity, damaged reputation with customers and in the marketplace, lost future sales and the cost of storing unsold goods. Financial analysts and accountants at your company can help you come up with the factors for your particular business.

If your website is generating profit for your business, you will for sure monitor it by an external monitoring service. The on-line market offers you to choose from different services to get uptime reports, statistics and get notifications as soon as your website is down. You can not let your customers to inform you about your own downtime.

To understand the importance of being aware of downtime, and to be alerted as soon as possible when a problem occurs, have a look at these numbers:

  • According to a report by Cumulus Research Partners website downtime, caused by problems such as network failures, costs European businesses more than ? 5 billion a year.
  • In the automotive industry downtime is often worth some $1.000 a minute.
  • According to a recent study conducted by ARC Advisory Group, accounting for nearly five percent of total North American production, more than $20 billion is lost each year due to unscheduled downtime. Clearly, the traditional "fail and fix" approach to maintenance is no longer a viable MRO strategy.
Many hosting providers guarantee 99 % uptime. 99 % uptime sounds good, but means that your site could be down more than 3.5 days a year, and in today's Internet that is unacceptable. Comparing to that, 99.9 % uptime is much better, but with 8 hours and 45 minutes of possible downtime do not have to be always enough. The table below shows the percentage of uptime and the related downtime per year.

99 % .......... 87 hours, 36 minutes (more than 3.5 days) 99.9 % ....... 8 hours, 45 minutes, 36 seconds 99.99 % ..... 52 minutes, 33.6 seconds 99.999 % .... 5 minutes, 15.36 seconds 99.9999 % .. 31.68 seconds

As you can see, a 99 % uptime may not sound too bad, but it can cost you quite a lot of loss in revenues.

There are more than 30 uptime monitoring websites worldwide, while some of those have also affiliate partners. Among those are: Alertra, AlertSite, Dotcom monitor, InternetSeer, Jaguard, RedAlert, SiteUptime, WatchMouse, WebsitePulse and others. Almost all of them offer some prepaid packages based on monthly fees, varying by number of possible monitored sites (servers), additional services and by the complexity of the service. The price of their basic prepaid package is $5 - $40 per month. For this price you can monitor only 1, or maximum of 3 devices, choose from quite a lot of protocols, allow to send notifications to multiple contacts via e-mail, IM, pager or SMS, allow to choose between daily, weekly, or monthly reports by email and of course uptime performance and statistics available on-line. The Professional packages can go up to $180 per month or even higher.

There are just two completely free 24/7 monitoring services: Montastic and mon.itor.us.

Montastic?s biggest advantage is simplicity of the service, while it offers just basic service including real time monitoring and alerting by e-mail one contact person ? the registred user, or by RSS feed, when the website is down and when it is back again. It allows to monitor only http websites, limited to the number of 100 (what is not a limit at all), checking it every 10 minutes from two different locations.

Meanwhile mon.itor.us provides network, website and server monitoring service supporting 11 protocols with possibility to monitor unlimited number of devices and alert unlimited number of contact persons by e-mail, RSS feed, IM message, pager or SMS. There are also other remarkable features as personalized interactive interface, where you can add server performance and availability tests, set daily, weekly or monthly reports sent by e-mail. Tests are performed from 3 geographically distributed servers, and they are always adding more interesting features as they are still in beta version.

Peter Cernak works at Sourcio. The company develops mon.itor.us and offers a wide range of IT services and Open Source solutions for small and medium-size businesses.

Labels: , , , ,

Thursday, February 28, 2008

Web Servers and Firewall Zones

Web and FTP Servers

Every network that has an internet connection is at risk of being compromised. Whilst there are several steps that you can take to secure your LAN, the only real solution is to close your LAN to incoming traffic, and restrict outgoing traffic.

However some services such as web or FTP servers require incoming connections. If you require these services you will need to consider whether it is essential that these servers are part of the LAN, or whether they can be placed in a physically separate network known as a DMZ (or demilitarised zone if you prefer its proper name). Ideally all servers in the DMZ will be stand alone servers, with unique logons and passwords for each server. If you require a backup server for machines within the DMZ then you should acquire a dedicated machine and keep the backup solution separate from the LAN backup solution.

The DMZ will come directly off the firewall, which means that there are two routes in and out of the DMZ, traffic to and from the internet, and traffic to and from the LAN. Traffic between the DMZ and your LAN would be treated totally separately to traffic between your DMZ and the Internet. Incoming traffic from the internet would be routed directly to your DMZ. Therefore if any hacker where to compromise a machine within the DMZ, then the only network they would have access to would be the DMZ. The hacker would have little or no access to the LAN. It would also be the case that any virus infection or other security compromise within the LAN would not be able to migrate to the DMZ.

In order for the DMZ to be effective, you will have to keep the traffic between the LAN and the DMZ to a minimum. In the majority of cases, the only traffic required between the LAN and the DMZ is FTP. If you do not have physical access to the servers, you will also need some sort of remote management protocol such as terminal services or VNC.

Database servers

If your web servers require access to a database server, then you will need to consider where to place your database. The most secure place to locate a database server is to create yet another physically separate network called the secure zone, and to place the database server there. The Secure zone is also a physically separate network connected directly to the firewall. The Secure zone is by definition the most secure place on the network. The only access to or from the secure zone would be the database connection from the DMZ (and LAN if required).

Exceptions to the rule

The dilemma faced by network engineers is where to put the email server. It requires SMTP connection to the internet, yet it also requires domain access from the LAN. If you where to place this server in the DMZ, the domain traffic would compromise the integrity of the DMZ, making it simply an extension of the LAN. Therefore in our opinion, the only place you can put an email server is on the LAN and allow SMTP traffic into this server. However we would recommend against allowing any form of HTTP access into this server. If your users require access to their mail from outside the network, it would be far more secure to look at some form of VPN solution. (with the firewall handling the VPN connections. LAN based VPN servers allow the VPN traffic onto the network before it is authenticated, which is never a good thing.)


Chris Weight is a writer for http://www.stekno.com , information for IT professionals

Labels: , , , ,

Monday, February 11, 2008

Have a big website? Worried about server load ?

If you have a big website, then it happened more that once to see it moving very slow. There is a way to do some testing and find out is the problems are caused by the hardware, or by the website itself.

Have we ever thought how big websites could be configured to handle massive amount of traffic? How thousands of businesses worldwide are facing challenges everyday to make sure there are no connection failures due to heavy load or congestion of traffic at the website.

The answer is straight, every organization will have to monitor and baseline amount of traffic by going for stress test to find out if the current hardware could be supportive enough to handle a specific amount of load. One such great software is the ?Web Application Testing? or WAPT, which is a great utility for any website?s sustainability. This software is load, stress and performance testing tool for web sites and intranet applications with web interface. WAPT is designed for MS Windows 2000/XP/2003 and Windows 98/Me operating systems. The question that should be asked is why should we consider WAPT or why should the organization consider Load or stress testing? We certainly believe, major performance issues would arise if stress test has not been performed. This could very well mean that after the server reaches a certain level of concurrent connection made by visitors, it would consume its hardware resources to process every visitor?s request. If there is a lot to process, the server might give priority to web application than its local resource ending up in a system crash.

Thus, the goal of WAPT is very simple; it helps the organization?s web servers to become active at every stage of stress, whether it?s a web development or website traffic processing power. WAPT can perform a stress test by simulating several thousands of concurrent connections to check the web server/website performance and if it finds any bottlenecks it would warn and suggest fixing this issue by recommending the very next thing.

There are lots of new features added in WAPT 4.0

  • - You can use multiple virtual profiles to test a single scenario
  • - There is support for IP spoofing where each virtual user can run with individual and unique IP address
  • - Each Virtual can be configured with different username and password and is compatible with Windows Integrated Authentication or Basic Configuration.
  • - You can see and configure the type of reports even a test run summary report is generated
  • - There is command line interface available
  • - There is a support for persistent cookies
  • - All the test scenario and profiles are stored in XML format
  • The Main features of WAPT 4.0

  • - You can have the application run and understand multiple languages
  • - There is cool recording feature which you can use to record any configuration and stress test simulations for later review or demonstrations as it supports playback of HTTPS/SSL 2.0 & 3.0 pages. You can also record the user connection speed using the keep-alive connections to a HTTP 1.0 or HTTP 1.1 pages or even HTTPS/SSL pages.
  • - You can generate data for run-times on specific scheduled intervals by randomizing the delay between the page hits.
  • - It also has a support for proxy servers for HTTP, HTTPS, SOCKS4 & 5 and supports cookies as well.
  • - All the authentication request can be handled using NTLM (windows Integrated Authentication) or using the basic authentication.
  • - If you would like to call the website by a different nameFind Article, then you also have the facility to add custom host headers
  • - All this the scenarios can be configured using the user friendly Wizard
  • - You can choose the reports to be either graphical or in plain text along with full virtual server logs
  • A must tool for administrator or other user who would to maintain their website efficiently.

    Source: Free Articles from ArticlesFactory.com


    Mircea Ionescu writes for CoreDownload, a shareware archive where you can find utilities like WAPT to test your server.

    Labels: , , ,

    Tuesday, November 27, 2007

    Dedicated Servers: A Summary

    What is dedicated hosting?
    This is a server which is owned by the hosting company which they will
    rent out to you for a monthly fee along with an allotment of bandwidth
    which you can use with it. This means that you get a whole server to
    yourself to use for what you desire, this is needed for scripts which
    use a lot of server resources (for example large message boards, for
    one of which I pay for a dedicated server). As a customer, you would
    have full control over the server and could change the configuration as
    required, a facility not available when you have to share a server with
    others. With a dedicated server, the web hosting company is responsible
    for the hardware as they own it, not the customer.

    What are the advantages of it?
    You can do anything you like on it that you like (although most hosts
    have acceptable use policies which state that illegal content is not
    allowed, and in some cases they prohibit connecting to IRC). This means
    that you can login to the server, set up programs as you desire, then
    run them without having to worry about the effects on server resources
    for other people. You can run games servers (for games such as
    Half-Life, etc), IRC servers or bots, or just run a web server which
    uses a lot of resources (and with a special setup which isn't found in
    shared hosting).

    What are the disadvantages?
    The main disadvantage is the cost, which will put many people off
    getting one. The cheapest seem to come at about $50/month, and the most
    expensive cost thousands of dollars each month. The price can be
    reflective of the quality (such as the cost of running - or your host
    renting a space in - the datacentre, the hardware in the server, the
    technical support provided by your host and so on), alternatively it
    can just be an over inflated price for what is a poor quality product.
    It's important to compare the prices and packages offered from several
    companies before coming to a decision, also you should ask your friends
    if they have any opinions on the matter, and research information about
    the hosting companies and datacentres - are the constantly offline due
    to DDOS attacks? do they have a poor record of customer service?

    Another disadvantage is the added responsibility involved in keeping
    the software on your server secure, for example you may have to update
    builds of apache, control panel software, etc as security holes are
    found.

    Is it for me?
    That depends, if you want to a game server then you'll need one - but
    it may be easier for you to buy one from a dedicated games server
    comapny, they know their stuff and would probably be able to install
    and configure the servers for you. However they would place
    restrictions on what you could do with the server and maybe the setup.
    If you want to run a small IRC server, bot or bouncer then you would
    probably be easiest paying a smaller fee to hire one of those from an
    IRC or shell provider company, also you don't have to worry about
    restrictive datacentre AUPs which prohibit IRC use.
    If you are starting a small web forum or site then you probably won't
    need one initially, wait until it grows and you can determine if you
    need the server to ensure further growth is ok.
    Otherwise you could possibly look into getting one, you could even
    email hosting providers asking what package they think your site would
    require (although take their replies with a pinch of salt, they could
    try to sell you stuff you don't actually need).
    vdhri.net is a website dedicated to providing free lessons and tutorials in many programming languages.

    Labels: , , ,