Re: [fw-wiz] More Syslog Questions

From: Devdas Bhagat (devdas_at_dvb.homelinux.org)
Date: 07/19/04

  • Next message: Bruce Platt: "[fw-wiz] Radio Ethernet Modem Experiences"
    To: firewall-wizards@honor.icsalabs.com
    Date: Tue, 20 Jul 2004 01:58:09 +0530
    
    

    On 19/07/04 08:10 -0500, Nathaniel Hall wrote:
    <snip>
    > Server 1 is connected to the main network. Server 2 is connected to Server
    > 1 using a cross over cable. Server 2 listens in promiscuous mode.
    > Physically the servers are secure and the only way to access Server 2 is
    > through KVM over IP.

    A more commonly proposed solution is to send the logs to server 1 and
    have server 2 on a spanned/mirrored port on the same switch. Server 2
    has no IP address on the network interface attached to the switch. Grab
    port 514/UDP traffic and dump to disk.

    Server 2 has a separate physical interface which can be reached from a
    different management subnet.

    IMHO, a server with a variant of syslogd listening on all ports and ssh
    only from a single host should be good enough. If the host has two
    physical interfaces, put them on two physically separate networks and
    have sshd listen only on the management interface.

    This protects you from everything except a syslogd exploit.

    Devdas Bhagat
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Bruce Platt: "[fw-wiz] Radio Ethernet Modem Experiences"

    Relevant Pages

    • ip based virtual hosting behind router
      ... I want to setup ipbased virtual hosting one a server behind a router. ... The server has one physical interface and one virtual interface. ...
      (comp.os.linux.networking)
    • RE: Some technical errors
      ... If the SMTP server is not running on port 25 TCP it is not a public ... Manager - Computer Assurance Services BDO Chartered Accountants & ...
      (Security-Basics)
    • Re: SRV RRs support in Internet Explorer?
      ... The port number could be implicit (i.e. ... At any point in time, a server could fail ... can't effectively LB or backup because NSs cache the records for the TTL ... I still don't see how SRV records would help backup or LB. ...
      (microsoft.public.win2000.dns)
    • Re: Still cant connect to RWW or OWA remotely
      ... I get 'cannot find server or dns error' on both ... TCP [port number]> to open the ports. ... As for error messages when I fail to access RWW with the laptop, ... network, no connection seems possible. ...
      (microsoft.public.windows.server.sbs)
    • Re: Outlook 2003 client
      ... Items' folder from the Send/Receive group for my account, ... Send/Receive to synchronize Outlook local data with the Exchange Server, ... Port 21 enable external and internal file transfer ... Port 80 enables all nonsecure browser access, ...
      (microsoft.public.windows.server.sbs)