Great Circle Associates Firewalls
(July 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: FW-1's SNMP
From: Sergio Bollini <sbollini @ lightech . com . ar>
Organization: LighTech
Date: Fri, 04 Jul 1997 14:12:31 +0300
To: firewalls @ greatcircle . com
Reply-to: sbollini @ lightech . com . ar

Hello everybody!
I have a question concerning FW-1's (v2.1, Solaris 2.5.1) SNMP daemon.
With the default communities, ISS Firewall Scanner was able to contact
it and fetch his MIB. Setting the communities to something non-obvious,
the scanner got no response from the port. But, isn't it vulnerable to a
brute-force password-guessing attack? It seems better to directly block
(with some rule o rules) any connection to the daemon.
I tried many rules for blocking SNMP (with the default communities), but
the scanner allways got the MIB. Even the default "catch-all" rule
doesn't take effect!
The question is: how can I block a connection to SNMP daemon?

As another question, is it possible to log a SecuRemote site creation? I
mean seeing when anybody configures my FW-1 as a site for his SecuRemote
client.

TIA
--
Sergio E. Bollini
LighTech                        Voice:  (54-1) 373-1141
Ayacucho 563. Piso 13 Dto "A"   FAX:    (54-1) 373-1215
Buenos Aires                    e-mail: sbollini @
 lightech .
 com .
 ar
Argentina                       URL:    http://www.lightech.com.ar

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

Indexed By Date Previous: Re: Calling the Horde
From: Sergio Bollini <sbollini @ lightech . com . ar>
Next: Re: IP Filters?
From: Darren Reed <avalon @ coombs . anu . edu . au>
Indexed By Thread Previous: Re: Remote Management
From: C Matthew Curtin <cmcurtin @ research . megasoft . com>
Next: [no subject]
From: "Marc H. Ingle" <elgnim @ primenet . com>

Google
 
Search Internet Search www.greatcircle.com