Re: [fw-wiz] More Syslog Questions

From: Devdas Bhagat (devdas_at_dvb.homelinux.org)
Date: 07/19/04

  • Next message: Bruce Platt: "[fw-wiz] Radio Ethernet Modem Experiences"
    To: firewall-wizards@honor.icsalabs.com
    Date: Tue, 20 Jul 2004 01:58:09 +0530
    
    

    On 19/07/04 08:10 -0500, Nathaniel Hall wrote:
    <snip>
    > Server 1 is connected to the main network. Server 2 is connected to Server
    > 1 using a cross over cable. Server 2 listens in promiscuous mode.
    > Physically the servers are secure and the only way to access Server 2 is
    > through KVM over IP.

    A more commonly proposed solution is to send the logs to server 1 and
    have server 2 on a spanned/mirrored port on the same switch. Server 2
    has no IP address on the network interface attached to the switch. Grab
    port 514/UDP traffic and dump to disk.

    Server 2 has a separate physical interface which can be reached from a
    different management subnet.

    IMHO, a server with a variant of syslogd listening on all ports and ssh
    only from a single host should be good enough. If the host has two
    physical interfaces, put them on two physically separate networks and
    have sshd listen only on the management interface.

    This protects you from everything except a syslogd exploit.

    Devdas Bhagat
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Bruce Platt: "[fw-wiz] Radio Ethernet Modem Experiences"

    Relevant Pages

    • Multihomed domain.
      ... Host records that map the name of the domain controller to its ... All client are using static ips on the physical interface, ... pointing to the server VPN's interface address. ... Firewall are both turned off on server and client. ...
      (microsoft.public.windows.server.active_directory)
    • ip based virtual hosting behind router
      ... I want to setup ipbased virtual hosting one a server behind a router. ... The server has one physical interface and one virtual interface. ...
      (comp.os.linux.networking)
    • RE: Some technical errors
      ... If the SMTP server is not running on port 25 TCP it is not a public ... Manager - Computer Assurance Services BDO Chartered Accountants & ...
      (Security-Basics)
    • Re: SRV RRs support in Internet Explorer?
      ... The port number could be implicit (i.e. ... At any point in time, a server could fail ... can't effectively LB or backup because NSs cache the records for the TTL ... I still don't see how SRV records would help backup or LB. ...
      (microsoft.public.win2000.dns)
    • Re: Still cant connect to RWW or OWA remotely
      ... I get 'cannot find server or dns error' on both ... TCP [port number]> to open the ports. ... As for error messages when I fail to access RWW with the laptop, ... network, no connection seems possible. ...
      (microsoft.public.windows.server.sbs)