Nexology Community
 
     
 
   

Go Back   Nexology Community > Support Zone > Plesk Control Panel

Reply
 
LinkBack Thread Tools Display Modes
Old 07-31-2010, 02:48 PM   #11
Adventurer
 
John W's Avatar
 
Join Date: Mar 2004
Location: Missouri, USA
Posts: 88
This was a helpful discussion. Reading it, though, I still don't understand exactly why the main domain should be on its own IP address not shared with any clients. Maybe someone can explain that?

Also, I have a client I just set up a web store and purchased an SSL certificate for. And then after purchasing the certificate I recalled that tech support had told me I would need an exclusive IP I think for that domain alone. Is that correct? And why is a "dedicated" IP necessary?

Thanks!
John W is offline   Reply With Quote
Old 07-31-2010, 06:44 PM   #12
Moderator
 
MikeMann's Avatar
 
Join Date: Jun 2002
Location: Los Angeles CA
Posts: 7,528
Quote:
Originally Posted by John W View Post
This was a helpful discussion. Reading it, though, I still don't understand exactly why the main domain should be on its own IP address not shared with any clients. Maybe someone can explain that?

Also, I have a client I just set up a web store and purchased an SSL certificate for. And then after purchasing the certificate I recalled that tech support had told me I would need an exclusive IP I think for that domain alone. Is that correct? And why is a "dedicated" IP necessary?
The SSL certificate is tied to an IP address through Plesk, this is why you need a dedicated IP address for that. Typically, you will want to have a dedicated IP address for each client who needs to have a SSL certificate setup for them. This would also be the reason it is suggested the main domain have its own IP address. For you to be able to add your own SSL certificate. At least, that's the way I see it.
__________________
Michael Mann

Michael Mann Desktop Publishing
Me On the Net: Facebook | Twitter | Squidoo | Yahoo! Contributor Network

Ubuntu Linux User since 08.04 (April 2008 release)

Virus? Computer slow? In LA? Downtown LA PC Techs can help.
MikeMann is offline   Reply With Quote
Old 07-31-2010, 11:10 PM   #13
Adventurer
 
John W's Avatar
 
Join Date: Mar 2004
Location: Missouri, USA
Posts: 88
Thanks for the reply, Mike.

I did also talk to tech support about the first question. I'm not sure, but it sounds to me almost as if the reason might be more procedural than technical: that an SSL is supposed to certify a particular web site and can only really do that accurately if there's only one domain associated with the IP the SSL cert is associated with.

But I may not have understood clearly.

As far as the second question goes, if I'm not running payments or a web store or logins on my main domain, then does it really matter if my main domain in on an IP shared between it and a number of clients?

I set things up long before I ran across the recommendation to have just your main domain on one IP and all clients on another. So I'm trying to understand whether there's a compelling reason or advantage to move all clients to the one domain. Also relevant is whether I'd likely run into technical hassles by doing so.
John W is offline   Reply With Quote
Old 08-01-2010, 04:55 AM   #14
HN Top Canine
 
NexDog's Avatar
 
Join Date: Jan 2002
Location: The Nexus
Posts: 13,328
We encourage users to place a main domain on one IP and then clients on another IP in case a client gets DoSed (so your site would still be up).

As Mike says, a cert is applied to an IP. We can apply the IP direct to the certificate in the IP Pool but then if you have multiple sites on that IP going to https on any domain would show that certificate.
__________________
Laurence - [HostNexus Administrator]

- Need Support? Quickest reponses are found at the Support Helpdesk!
- Stay in touch! Make sure you are subscribed to our Lists.
NexDog is offline   Reply With Quote
Old 08-01-2010, 05:01 AM   #15
You and what a
 
RobbieLePommie's Avatar
 
Join Date: Aug 2002
Location: Sydney
Posts: 5,928
John,

SSL is one reason.

The other critical reason: If one of your clients gets attacked by a DDOS (Denial of Service) attack, the techs will block access to the IP address being blocked.

If you use shared: all the clients on that server get affected - you won't be popular

If you use you MAIN exclusive IP, your MAIN website goes down as well as all your clients'. Clients won't know what's up, and you need to move everyone (inlcuding yourself)

If you use your SECOND exclusive IP, your clients go down, but your website stays up. You can then move your good clients to your first IP address, whilst the nasty one is fixed. Then restore later.

DDOS attacks on "casual" sites are rare, but you don't know if they happen or what triggers them. So this minimises the damage.
__________________
Rob
----------------------------
For your information, there's a lot more to ogres than people think.
RobbieLePommie is offline   Reply With Quote
Old 08-01-2010, 05:04 AM   #16
You and what a
 
RobbieLePommie's Avatar
 
Join Date: Aug 2002
Location: Sydney
Posts: 5,928
Doh - type longer explinations, Laurence. Then I can finish mine first
__________________
Rob
----------------------------
For your information, there's a lot more to ogres than people think.
RobbieLePommie is offline   Reply With Quote
Old 08-01-2010, 07:40 PM   #17
Adventurer
 
John W's Avatar
 
Join Date: Mar 2004
Location: Missouri, USA
Posts: 88
Smile

Thanks for the replies and explanations, Laurence & Rob. Very helpful and much appreciated!
John W is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 04:16 AM.


Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.0 RC1
Copyright ©2001 - 2009, HostNexus