Great Circle Associates Firewalls
(October 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Access to MS routers
From: foxtrot @ xs4all . nl
Date: Mon, 2 Oct 1995 20:11:23 +0100
To: firewalls @ GreatCircle . com

This is my second question about Morning Star routers on this list (BTW, 
thanks to the people who responded the first time)....

Our MS router is situated between an application gateway (AG) on our 
internal network and a dial-up PPP connection to our Internet provider.

First, as I'm using one (static dial-up) route to our service provider and 
one route to the AG I suppose I can disable dynamic routing on the MS router 
by deleting 'gated'  and enable static routing with the line 'route add 
default <<<MS-interface address>>' in RC.BOOT. Am I right????

Second, I don't want any service running on my router, so I want to delete 
the files 'services'. That's OK??? Or should there be one entry for 'syslog' 
(514/udp)? Why should there be a nfsd on the router???? Is it safe to delete 
all protocol entries in the file 'protocol' but IP and TCP (I don't want any 
other protocols)???

Third, what's the use of the file smp.parties (SNMP???) and ACL.parties????? 
Can I delete the files 'vectors', 'tzposixrules', 'view.parties'???

Fourth, in the rc.boot file there's a line which reads 'getty tty2 9600 
nowait respawn'. Does this mean that more than one person is allowed login 
in simultaneously??? Should 'nowait' be replaced with 'wait'???

The reason for asking these questions is that after bankrupcy of our 
firewall-supplier we haven't goy any documentation at all and we are 
evaluating our current firewall. The setup should be as minimum as possible.

Again, my thanks in advance for any response,

Adriaan


Indexed By Date Previous: RE: -Reply
From: "Robert E. Bowes" <REBowes @ smtpgate . read . tasc . com>
Next: Re: non-root low ports
From: Scott Barman <scott @ Disclosure . COM>
Indexed By Thread Previous: RE: -Reply
From: "Robert E. Bowes" <REBowes @ smtpgate . read . tasc . com>
Next: LAWZ
From: "A. Padgett Peterson, P.E. Information Security" <PADGETT @ hobbes . orl . mmc . com>

Google
 
Search Internet Search www.greatcircle.com