Networking and System AdministrationUnit 77 min read
Web & Mail Servers: Config, Protocols & Security
Unit 7 of Networking and System Administration covers web servers (Apache/Nginx), mail servers (Postfix/Dovecot), protocols (HTTP/HTTPS, SMTP/IMAP), virtual hosting, security hardening, and troubleshooting—with real-world examples from eSewa, Ncell, and global platforms.
Core Concepts
Web Servers: The Backbone of the Internet
A web server is software that delivers web content (HTML, CSS, JS) to clients via HTTP/HTTPS. It processes requests, serves static/dynamic content, and manages hosting environments.
Key Components
- HTTP/HTTPS: Protocols for data exchange.
- HTTP (HyperText Transfer Protocol): Unencrypted, port 80.
- HTTPS (HTTP Secure): Encrypted (TLS/SSL), port 443.
- Apache vs. Nginx:
- Apache: Modular, supports
.htaccess, widely used (e.g., WordPress). - Nginx: Lightweight, high-performance, reverse proxy capabilities.
- Apache: Modular, supports
classDiagram
class WebServer {
+Process HTTP/HTTPS requests
+Serve static/dynamic content
+Log access/error events
}
class Apache {
+Modular architecture
+Supports .htaccess
+Port 80/443
}
class Nginx {
+Event-driven model
+Reverse proxy support
+Port 80/443
}
WebServer <|-- Apache
WebServer <|-- NginxWorked Example: Hosting a Website on Apache
- Install Apache on Ubuntu:
sudo apt update && sudo apt install apache2 - Configure a virtual host (
/etc/apache2/sites-available/example.conf):<VirtualHost *:80> ServerName example.com DocumentRoot /var/www/example ErrorLog ${APACHE_LOG_DIR}/error.log CustomLog ${APACHE_LOG_DIR}/access.log combined </VirtualHost> - Enable the site and restart Apache:
sudo a2ensite example.conf && sudo systemctl restart apache2 - Test via browser:
http://example.com.
In the Real World
eSewa (Nepal):
- Uses Nginx as a reverse proxy to balance traffic across multiple backend servers (Apache/PHP-FPM). This ensures low latency during peak hours (e.g., festival seasons).
- HTTPS (TLS 1.3) encrypts all transactions (bill payments, top-ups) to prevent MITM attacks.
Ncell’s Mobile Portal:
- Hosts dynamic content (balance checks, data plans) using Apache with PHP. The portal’s
.htaccessrules restrict access to authorized users only (e.g., logged-in customers). - SMTP relay (Postfix) sends OTPs via email/SMS for 2FA.
- Hosts dynamic content (balance checks, data plans) using Apache with PHP. The portal’s
YouTube (Global):
- Uses Nginx for CDN edge caching to deliver videos faster. Static assets (thumbnails, JS) are served via HTTP/2, while dynamic content (comments, recommendations) uses HTTPS.
- Virtual hosting allows
youtube.comandyoutu.beto share the same backend infrastructure.
Mail Servers: Delivering Electronic Messages
A mail server handles sending (SMTP), receiving (IMAP/POP3), and storing emails. Key components:
- Postfix: SMTP server (sending).
- Dovecot: IMAP/POP3 server (receiving).
- SpamAssassin: Filter for unwanted emails.
SMTP Workflow (Trace)
- Client (e.g., Gmail) connects to SMTP server (port 25/587).
- Handshake:
sequenceDiagram participant Client as Email Client (Gmail) participant SMTP as Mail Server (Postfix) Client->>SMTP: EHLO example.com SMTP-->>Client: 250 Hello Client->>SMTP: MAIL FROM: <sender@example.com> SMTP-->>Client: 250 OK Client->>SMTP: RCPT TO: <recipient@ncell.com> SMTP-->>Client: 250 OK Client->>SMTP: DATA\nFrom: sender@example.com\nTo: recipient@ncell.com\nSubject: Hello\n\nBody... SMTP-->>Client: 250 Message accepted
- Postfix queues the email and delivers it to Dovecot (IMAP server).
Worked Example: Configuring Postfix for eSewa
- Install Postfix:
sudo apt install postfix - Edit
/etc/postfix/main.cf:myhostname = mail.esewa.com mydomain = esewa.com myorigin = $mydomain inet_interfaces = all mydestination = $myhostname, localhost.$mydomain, localhost relayhost = - Restart Postfix:
sudo systemctl restart postfix - Test sending an email:
echo "Test email" | mail -s "Subject" recipient@ncell.com
Virtual Hosting: Sharing One Server
Virtual hosting allows multiple websites to run on a single server using:
- Name-based: Different
ServerNamedirectives (e.g.,example.com,test.example.com). - IP-based: Dedicated IP per site (rare today).
Comparison Table
| Feature | Name-Based Hosting | IP-Based Hosting |
|---|---|---|
| Port Requirement | Single (80/443) | Multiple IPs needed |
| Configuration | Simpler (Apache/Nginx) | Complex (requires IPs) |
| Performance | Slightly slower (DNS lookup) | Faster (direct IP routing) |
| Use Case | Shared hosting (e.g., Daraz) | Legacy systems, SSL per IP |
Example: A hosting provider uses name-based virtual hosting to serve 100 websites on one Apache server, each with its own DocumentRoot and SSL certificate.
Security Hardening
HTTPS Everywhere:
- Obtain a Let’s Encrypt certificate (free) via Certbot:
sudo certbot --apache -d example.com - Enforce HTTPS redirects in Apache:
<VirtualHost *:80> ServerName example.com Redirect permanent / https://example.com/ </VirtualHost>
- Obtain a Let’s Encrypt certificate (free) via Certbot:
Mail Server Security:
- Enable TLS in Postfix (
/etc/postfix/main.cf):smtpd_tls_cert_file = /etc/ssl/certs/ssl-cert-snakeoil.pem smtpd_tls_key_file = /etc/ssl/private/ssl-cert-snakeoil.key - Use SPF/DKIM/DMARC to prevent spoofing (e.g.,
v=spf1 include:_spf.google.com ~allin DNS).
- Enable TLS in Postfix (
Firewall Rules:
- Allow only HTTP/HTTPS/SMTP ports:
sudo ufw allow 80/tcp sudo ufw allow 443/tcp sudo ufw allow 25/tcp sudo ufw enable
- Allow only HTTP/HTTPS/SMTP ports:
Troubleshooting Common Issues
| Issue | Cause | Solution |
|---|---|---|
| 500 Internal Server Error | PHP syntax error or permissions | Check /var/log/apache2/error.log |
| SMTP Connection Refused | Firewall blocking port 25 | sudo ufw allow 25/tcp |
| Email Not Delivered | SPF/DKIM misconfiguration | Verify DNS records (dig TXT example.com) |
| Slow Website | High CPU/memory usage | Optimize Apache/Nginx or upgrade server |
Exam Tip
Diagrams Are Key:
- Draw HTTP request/response cycles (e.g., GET/POST flows).
- Sketch mail server workflows (SMTP → Postfix → Dovecot).
- Compare Apache vs. Nginx in a table (use cases, performance).
Configuration Snippets:
- Memorize Apache virtual host and Postfix
main.cfkey directives. - Know how to enable HTTPS with Let’s Encrypt.
- Memorize Apache virtual host and Postfix
Real-World Scenarios:
- Explain how eSewa uses Nginx for load balancing during Diwali sales.
- Describe Ncell’s SMTP relay for OTP delivery (SMTP → Postfix → SMS gateway).
Security Questions:
- Always mention TLS, SPF, and firewall rules when asked about hardening.
- For mail servers, include DKIM/DMARC in answers.
Based on the TU BITM syllabus for Networking and System Administration (IT271), unit 7.
Discussion
Loading…