Re: tcpwrapped rpcbind/portmap?
From: Warren Belfer (belfer@ha2mpk-mail.Eng.Sun.COM)Date: 08/22/01
- Previous message: Vladimir Ivanov: "Re: tcpwrapped rpcbind/portmap?"
- Maybe in reply to: Geoff Collis: "tcpwrapped rpcbind/portmap?"
- Next in thread: Cy Schubert - ITSD Open Systems Group: "Re: tcpwrapped rpcbind/portmap?"
- Reply: Cy Schubert - ITSD Open Systems Group: "Re: tcpwrapped rpcbind/portmap?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Message-Id: <200108221651.JAA27240@phys-ha2mpka-16.Eng.Sun.COM> Date: Wed, 22 Aug 2001 09:51:02 -0700 (PDT) From: Warren Belfer <belfer@ha2mpk-mail.Eng.Sun.COM> Subject: Re: tcpwrapped rpcbind/portmap? To: focus-sun@securityfocus.com
A host based firewall is an important line of defense on any host,
even on non-hostle networks. Malicious or clueless insiders often
cause more damage than external hackers. I've been running ipfilter
(or Sunscreen) on Solaris on every host for years and I've yet to see
any significant performance penalties, unless your machine is already
very close to the edge. Ipfilter does require maintaining another
package, but any host based firewall requires that.
HTH
warren
>Yes, IPfilter built as a 64-bit LKM is certainly one line of defense.
>Concerns have been raised about the performance impact of using an
>IPfilter LKM with Solaris, and on top of that it's an additional
>package to maintain across all of one's systems, as opposed to an
>incremental feature in an existing package.
>
>In any case, as noted by Geoff Collis in another message within this
>thread it is sometimes desirable to have multiple layers performing the
>same security functions (ACL checking in this case) in order to decrease
>the probability of failure.
>
>-Trevor
>
>--
>Trevor Fiatal -- trevor@seven.com -- http://www.seven.com/
>Co-Founder
>Seven
>510.967.4556 (work/mobile)
>510.401.8054 (vmail/fax)
- Previous message: Vladimir Ivanov: "Re: tcpwrapped rpcbind/portmap?"
- Maybe in reply to: Geoff Collis: "tcpwrapped rpcbind/portmap?"
- Next in thread: Cy Schubert - ITSD Open Systems Group: "Re: tcpwrapped rpcbind/portmap?"
- Reply: Cy Schubert - ITSD Open Systems Group: "Re: tcpwrapped rpcbind/portmap?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|