SunScreen 3.2 Queries

From: Crist Clark (crist.clark_at_globalstar.com)
Date: 02/18/05

  • Next message: McEwan, Ryan: "Solaris user configuration"
    Date: Fri, 18 Feb 2005 12:59:17 -0800
    To: Sun Managers <sunmanagers@sunmanagers.org>
    
    

    I am awash in documentation for SunScreen that all wants to address much
    more complicated situations than I have. What I have is a multi-homed
    host which I want to protect. This host is NOT a router. I want to put
    severe ingress and egress filters on one of its interfaces. I want no
    restrictions on other interfaces. I would like to do all administration
    at the CLI and kill off the near-useless GUI. I am running Solaris 9
    (sparc) with SunScreen 3.2.

    So my questions are:

            I cannot see where in rules I can apply them to only specific
            interfaces. How do I do this? Can I do this?

            Without the ability to set rules per-interface, the anti-spoofing
            abilities of the firewall become essential, but I can find little
            documentation on what anti-spoofing does or does not do and how
            it works in the SunScreen 3.2 documentation. How does it work?

            Will SunScreen function properly if I kill off the Apache server
            and Java processes it starts up? What's the "correct" way to
            stop them from starting?

    Before someone says "IPFilter," yes, I know, it would be trivial to do
    this in IPFilter. But management wants a Sun-supported product blah-blah
    (I know IPFilter is in 10, but I don't think its supported in 9. I would
    love to be corrected on that.)

    -- 
    Crist J. Clark                               crist.clark@globalstar.com
    Globalstar Communications                                (408) 933-4387
    _______________________________________________
    sunmanagers mailing list
    sunmanagers@sunmanagers.org
    http://www.sunmanagers.org/mailman/listinfo/sunmanagers
    

  • Next message: McEwan, Ryan: "Solaris user configuration"

    Relevant Pages

    • Re: single host netmask (255.255.255.255)
      ... The routes from three interfaces, propagate via OSPF to the rest of network.... ... One way is to remember IP addresses assigned to each interfaces, but more smart solution is to assign to this machine one EXTERNAL LOOPBACK address (single IP with mask 255.255.255.255, in other words SINGLE HOST assigned to Microsoft loopback adapter), and propagate this address ... The address 255.255.255.255 denotes a broadcast on a local hardware network, ...
      (microsoft.public.win2000.networking)
    • Re: hostnames and interfaces
      ... > interface) and routers (multiple interfaces) can one define multiple ... > host names and IP addresses (strickly speaking that is what dns etc sees?) ... this can be a problem with a multi-homed host: ... Any machine will have a hostname -- that is the name which gets ...
      (freebsd-questions)
    • Re: Two taps, one IP?
      ... either my Debian guests or Ubuntu host wrong. ... This creates two tap interfaces on the Ubuntu host, ... But each is unable to wget the ... The error message suggests some sort of routing problem, ...
      (Debian-User)
    • Re: jails and multple interfaces
      ... The server has two network interfaces, I am configuring one for host ... All the services running on the host are configured to bind to the host ... I have the jail host's services all binding to the first interfaces ip, ...
      (freebsd-stable)
    • Re: [patch 2/6] [Network namespace] Network device sharing by view
      ... Example as a prefix: guest0-eth0. ... be interesting to have the host also manage these interfaces ... guest eth0 created on the host side ...
      (Linux-Kernel)