Re: Locking Down a Linux Box

From: Alex Collins (alex@geoquark.com)
Date: 12/23/01


From: Alex Collins <alex@geoquark.com>
To: Kevin Robitaille <kevin.robitaille@ergogroup.com>, focus-linux@securityfocus.com
Date: Sun, 23 Dec 2001 10:17:04 +0000

On Friday 21 December 2001 1:30 pm, Kevin Robitaille wrote:
> Any one out there know good reference for securing a
> Linux 7.2 Server OS. I'm new to using Linux and need
> to lock down a system for use as an IDS Sensor. Any
> help would be appreciated.

How were you going to set it up?

I assume you would go for 2 NICs, one for connection to the network segment
to be watched, and one to a management lan - this would have any tools running
that you use for managing the sensor.

The NIC on the watched lan would best be in Promicuous mode and configured
without an IP address (hence it cannot be directly reached by other computers
on that network.

This then allows you to manage the sensor (retrive logs / view alerts) but
without making the Sensor available at the IP level on the network you are
watching.

Alex Collins
 



Relevant Pages

  • Re: Is my system secure? What else should I do?
    ... > network functionality for my computing activities (browsing, ... My network shows No presence to the outside world, ... browsing and open for secure browsing. ... Linux is no longer protecting the other computers/devices on your local ...
    (comp.os.linux.security)
  • Re: LONWorks vs. Ethernet
    ... >Linux PC, which also sends signals back to open and close the relays. ... >and how much the chips, transceivers, and external components cost ... >it's far too sensitive to wiring imperfections, and the network ... The AVR is a far superior device to the Neuron chip as far performance ...
    (comp.arch.embedded)
  • Re: What are folks doing to keep the skys dark? monitoring network
    ... powered, 2 channel, wireless, house keeping, root en toot en, all weather device that needs a care taker to clean the windows and calibrate the sensor. ... A calibration cap has a light source and calibrated detector that is used to check the window loss in the field. ... We hope to deploy night sky brightness stations using the net every where funding and the network will let us. ... The calibration of this instrument represents yet another photometry system as V does not directly correlate with CM500 glass photometry. ...
    (sci.astro.amateur)
  • Re: OT: Computer stuff
    ... running five home computers and admin nine more at the local library). ... I know for a fact that there is an anti-virus program available for Linux. ... It says it does not support power management under SMP as the kernel loads. ... I have taught Network+, and A+. ...
    (alt.support.diabetes)
  • Re: setting computer name
    ... If your network interfaces use DHCP, you can configure the DHCP server ... > however it did not have 'multi on', which I saw as being needed according to the Linux how-to help guides. ... > on how to install gcc 2.95.3 on Linux. ...
    (Fedora)