Re: ipf, Sunscreen or ?
From: Scott Wilson (swilson_at_uchicago.edu)
Date: 10/22/03
- Previous message: Pedro Torradinhas: "Re: ipf, Sunscreen or ?"
- In reply to: Brad Arlt: "Re: ipf, Sunscreen or ?"
- Next in thread: Valerie Anne Bubb: "Re: ipf, Sunscreen or ?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Wed, 22 Oct 2003 10:36:14 -0500 (CDT) To: focus-sun@securityfocus.com
We've used IPF and Sunscreen for a while now, and I couldn't imagine
running a machine without something similar.
We used IPF on all of our Solaris 7 and 8 boxes, and we use Sunscreen on
all of our Solaris 9 boxes.
I use the command line mode (ssadm), so running a web server to get a GUI
isn't an issue.
The only things that are mildly annoying is that you can't use numbers for
IPs or ports in the rules. You have to first define the nubmers, then use
the aliases in the rules. I guess its good in some ways, since with
decent names you never run into the "So why did I open that port to that
machine?" issue, but it does take a little longer. The only other
annoyannce is that changing the rules using "ssadm edit" doesn't actually
do anything until you either reboot, or run "ssadm activate".
All in all though, Sunscreen works great.
Scott Wilson Manager / Lead System Administrator
swilson@uchicago.edu NSIT - TaRT - Systems & Servers
On Wed, 22 Oct 2003, Brad Arlt wrote:
> On Tue, Oct 21, 2003 at 04:49:51PM -0700, Chris Pelton wrote:
> > boxes but was burned awhile back by ipf (could have been a
>
> There were 2 or 3 versions that had problems booting. That is fixed.
> I have noticed a large CPU usage when sending lots of data, but
> otherwise love IPF.
>
> I will be trying SunScreen this morning (to get around high CPU use
> while sending), but don't have an opinion as yet.
> -----------------------------------------------------------------------
> __o Bradley Arlt Security Team Lead
> _ \<_ arlt@cpsc.ucalgary.ca University Of Calgary
> (_)/(_) Joyously Canadian Computer Science
>
- Previous message: Pedro Torradinhas: "Re: ipf, Sunscreen or ?"
- In reply to: Brad Arlt: "Re: ipf, Sunscreen or ?"
- Next in thread: Valerie Anne Bubb: "Re: ipf, Sunscreen or ?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|