Wiki, virtual hosts, port mapping, and frustration

I am a learning admin, and generally try and work through things myself until this time. I am pretty sure I need some suggestions.

I'm running an xserve 2x2 xeon, with a fully updated leopard server. I am not using postfix (I've switched to Exim), but my problems are surrounding what many server operators here may be doing... virtual hosting and trying to get all the services started...

Now I won't get into Kerberos in this post... as that's an issue between me and my ISP for not giving me either cname or rdns service (a beef I'm pursuing)..

So what am I doing...
1) one internally facing port 192.168... offering AFP and iCal service.
2) external port (wan side - but not fully reverse dns qualified) serving Web, FMServer, Wiki (trying) and Mail (exim) and a PHP based fileserver.
Notes on external port: I use dyndns to map all virtual domains to the right ports on my server. for example, domain1.ca is default 80, domain2.ca is 81, domain2.ca is 8081, domain4.ca is 8082 and so on. There are several. I pay for DynDNS to offer reverse DNS service to me by setting my server to only use their rDNS services (not including dns running on the server for the domain1.ca only which is the default).

The problem:
The main domain for everything works. Wiki works, user blogs works, mail works for all domains (separate from Apples anyway), iCal works fine, Open directory on the server runs fine (however without Kerberos - changeip still picks up ISP's cname for IP). What DOESN'T work... is the Wiki for all the port shifted domains. So any domain not on 80 doesn't work.

I can get the domain wiki to show on the wiki home page, but when clicked get the "404: No group with that name (domain2) hosted on this server" message. Even if I ensure the correct URL path is used.. still the same error.

Do I need to do something special to get the port shifted domains to work on the wiki?
All other aspects for them works fine, including realm access set through OD.

When I blank out the domain in the admin->sites-> for say the port 81 site it works. I of course can't leave it like this with 10 + sites.... and they can't all be blank.
So what am I missing here... a bad DNS entry that leopard is picking up on?

THe way dyndns works is the www.domain2.ca is actually mapped to www2.domain2.ca:81 and is cloaked so the user only sees www.domain2.ca in their browser.

Thoughts anyone. I know I'm pushing the envelope, but this seems like I'm just missing something I've overlooked here.

Thanks in advance.

Chris

XServe 2x2 Dual Core Xeon, Mac OS X (10.5.4), MBP, Graphite, Beige G3, ibook G4, and more

Posted on Aug 27, 2008 8:55 AM

Reply
8 replies

Aug 27, 2008 11:25 AM in response to Paul Vail

Hi,

Thanks very much for the reply, and yes when I change some to all be on the 80 port it does work. I just don't understand why the wikid server doesn't allow the port shift.

Now maybe my understanding of DNS and certificates is not good enough but I am not aware of how I can have multiple domains under ssl and have them each served a different certificate if they're all at 443? is that not allowed anyhow?

This is one of my reasons for the port shifting... the others were I just got in the habit of it. I can put "some" back to 80 to fix that issue.

But does anyone know of a way to get it to work with the shifted ports, 443, 8443, 8043, 80**, etc.

if not I'm guessing I can only have one wiki under ssl - is this right?

Thanks,

chris

Aug 27, 2008 8:16 PM in response to iconindustries

You don't want to do VH for certs by port forwarding. The server isn't the only sw that will break. You'll run afoul of careful planning by your visitors for firewall rules and much more. IP Aliasing is the tool to use for running multiple VH certs.

If you need more documentation, I can send you a link to some brief notes I have on using the server for hosting. They are incomplete, but might be useful in some capacity.

Aug 28, 2008 2:15 AM in response to Paul Vail

Thanks very much Paul. I would like those docs for when I can do that. Right now my ISP is only giving me two IP's (one fixed one dynamic) and they don't have any immediate plans for expansion. There is only one other ISP in my area that offers business service (who I don't like - but might have to move to...). So right now I have only one IP for the external side.

I will look into this for sure though, because I would like to set it up properly. I'll just have to look into an better ISP who offers rDNS and mulitple ip packs then.

Thanks for everyones input.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Wiki, virtual hosts, port mapping, and frustration

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.