Great Circle Associates Firewalls
(February 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Isolated box...
From: "Brian T. Wightman" <wightman @ sol . acs . uwosh . edu>
Date: Tue, 13 Feb 1996 01:08:04 -0600
To: firewalls @ greatcircle . com

Hi all,

This may not be entirely relevant for firewalls, but I think it is
close, so...

I have an opportunity to get a couple of old Sun IPCs to use to
provide services such as RARP, bootp/dhcp, bootparams, etc as well as
some network listening.  RARP under SunOS 4.1.n needs the /dev/nit
device, which I do not want to put on an "open" machine.

Would stripping all services from /etc/inetd, stopping nfs, NIS, etc,
basically only allowing console logins, and only supporting sendmail
going out, ftp going out, pulling unneeded devices/filesystem
types/etc out of the kernel, etc be sufficient protection for this
box, or are there some other parameters that would need to be tweaked
either in the kernel at run time or in some header files?

Basically I would like to lock that /dev/nit device into a controled
environment.  It would be a pain in the but to administer, but it
should not require much in the way of maintenance.

Brian T. Wightman                  wightman @
 sol .
 acs .
 uwosh .
 edu
Academic Computing, UW Oshkosh     wightman @
 oshkoshw .
 bitnet
800 Algoma Blvd, Dempsey Hall 307  http://www.uwosh.edu/faculty_staff/wightman
Oshkosh, Wisconsin  54901          Phone: (414) 424-3020                


Follow-Ups:
Indexed By Date Previous: Re: your mail
From: Rabid Wombat <wombat @ mcfeely . bsfs . org>
Next: Proxy for X.400
From: pc @ bim . be (Philippe Cayphas)
Indexed By Thread Previous: [no subject]
From: Tham Huei Hwan <Tham . Huei . Hwan @ bass . com . my>
Next: Re: Isolated box...
From: Doug Hughes <Doug . Hughes @ Eng . Auburn . EDU>

Google
 
Search Internet Search www.greatcircle.com