<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Permit root login through one network (NIC) only in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/permit-root-login-through-one-network-nic-only/m-p/3471823#M211899</link>
    <description>Do not give that ip address to anyone!!&lt;BR /&gt;Else, I can think of ipfilter, tcp wrappers&lt;BR /&gt;&lt;BR /&gt;Anil</description>
    <pubDate>Wed, 26 Jan 2005 14:42:19 GMT</pubDate>
    <dc:creator>RAC_1</dc:creator>
    <dc:date>2005-01-26T14:42:19Z</dc:date>
    <item>
      <title>Permit root login through one network (NIC) only</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/permit-root-login-through-one-network-nic-only/m-p/3471822#M211898</link>
      <description>I need a secure method of permitting root access when a login comes through one NIC card and not the other.&lt;BR /&gt;&lt;BR /&gt;For example, if my NICs are:&lt;BR /&gt;&lt;BR /&gt;10.26.100.10 and&lt;BR /&gt;231.62.100.231&lt;BR /&gt;&lt;BR /&gt;is it possible to permit root access through the 10.X.X.X NIC and *NOT* through the 231.X.X.X NIC?&lt;BR /&gt;&lt;BR /&gt;I know the easiest method is be secure with the root password but allowing access from only within a particular physical environment would make me feel more comfortable.&lt;BR /&gt;&lt;BR /&gt;Any and all help appreciated.&lt;BR /&gt;&lt;BR /&gt;PK&lt;BR /&gt;</description>
      <pubDate>Wed, 26 Jan 2005 14:39:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/permit-root-login-through-one-network-nic-only/m-p/3471822#M211898</guid>
      <dc:creator>Philip Kernohan</dc:creator>
      <dc:date>2005-01-26T14:39:16Z</dc:date>
    </item>
    <item>
      <title>Re: Permit root login through one network (NIC) only</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/permit-root-login-through-one-network-nic-only/m-p/3471823#M211899</link>
      <description>Do not give that ip address to anyone!!&lt;BR /&gt;Else, I can think of ipfilter, tcp wrappers&lt;BR /&gt;&lt;BR /&gt;Anil</description>
      <pubDate>Wed, 26 Jan 2005 14:42:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/permit-root-login-through-one-network-nic-only/m-p/3471823#M211899</guid>
      <dc:creator>RAC_1</dc:creator>
      <dc:date>2005-01-26T14:42:19Z</dc:date>
    </item>
    <item>
      <title>Re: Permit root login through one network (NIC) only</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/permit-root-login-through-one-network-nic-only/m-p/3471824#M211900</link>
      <description>I asked a similar question in the past, and was pointed to ipfilter:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://software.hp.com/portal/swdepot/displayProductInfo.do?productNumber=B9901AA" target="_blank"&gt;http://software.hp.com/portal/swdepot/displayProductInfo.do?productNumber=B9901AA&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 26 Jan 2005 14:43:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/permit-root-login-through-one-network-nic-only/m-p/3471824#M211900</guid>
      <dc:creator>Ken Penland_1</dc:creator>
      <dc:date>2005-01-26T14:43:09Z</dc:date>
    </item>
    <item>
      <title>Re: Permit root login through one network (NIC) only</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/permit-root-login-through-one-network-nic-only/m-p/3471825#M211901</link>
      <description>Run an sshd daemon that just listens on that specific interface and set PermitRootlogin to yes.</description>
      <pubDate>Wed, 26 Jan 2005 14:52:50 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/permit-root-login-through-one-network-nic-only/m-p/3471825#M211901</guid>
      <dc:creator>Kevin Wright</dc:creator>
      <dc:date>2005-01-26T14:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: Permit root login through one network (NIC) only</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/permit-root-login-through-one-network-nic-only/m-p/3471826#M211902</link>
      <description>The IP addresses are for example only, they're not actually mine.&lt;BR /&gt;&lt;BR /&gt;I'll check out the suggestions and assigns points shortly.&lt;BR /&gt;&lt;BR /&gt;PK</description>
      <pubDate>Wed, 26 Jan 2005 15:13:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/permit-root-login-through-one-network-nic-only/m-p/3471826#M211902</guid>
      <dc:creator>Philip Kernohan</dc:creator>
      <dc:date>2005-01-26T15:13:33Z</dc:date>
    </item>
    <item>
      <title>Re: Permit root login through one network (NIC) only</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/permit-root-login-through-one-network-nic-only/m-p/3471827#M211903</link>
      <description>Ken / Anil,&lt;BR /&gt;&lt;BR /&gt;No, you can't use IPFilter.&lt;BR /&gt;&lt;BR /&gt;IPFilter can only allow/deny access based on IP&lt;BR /&gt;address / port #, but it does not have any control &lt;BR /&gt;over the user name. For ex, you allow/deny telnet &lt;BR /&gt;from 10.26.100.10, you have to allow/deny ALL &lt;BR /&gt;users from that machine.&lt;BR /&gt;&lt;BR /&gt;- Biswajit&lt;BR /&gt;</description>
      <pubDate>Wed, 26 Jan 2005 20:50:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/permit-root-login-through-one-network-nic-only/m-p/3471827#M211903</guid>
      <dc:creator>Biswajit Tripathy</dc:creator>
      <dc:date>2005-01-26T20:50:28Z</dc:date>
    </item>
    <item>
      <title>Re: Permit root login through one network (NIC) only</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/permit-root-login-through-one-network-nic-only/m-p/3471828#M211904</link>
      <description>If you are having problems with your root password being locked from the 231 network, I have a daemon I developed called monbad that effeictively stops the script kiddies.&lt;BR /&gt;&lt;BR /&gt;You can probably put some code into your /etc/profile that can pick up where the login came from and reject the user. But that will only work for users that have the password.&lt;BR /&gt;&lt;BR /&gt;IPFilter is designed to block ports and protocols, not individual users.&lt;BR /&gt;&lt;BR /&gt;Let me know if you meed monbad and I'll post it somewhere. It is designed for secureshell logins but can easily be upgraded to handle telnet.&lt;BR /&gt;&lt;BR /&gt;Letting root log on with telnet is a bad idea because the password goes through the network in clear text.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Wed, 26 Jan 2005 23:19:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/permit-root-login-through-one-network-nic-only/m-p/3471828#M211904</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2005-01-26T23:19:59Z</dc:date>
    </item>
    <item>
      <title>Re: Permit root login through one network (NIC) only</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/permit-root-login-through-one-network-nic-only/m-p/3471829#M211905</link>
      <description>SEP,&lt;BR /&gt;&lt;BR /&gt;I'd be interested in monbad if you can share it?&lt;BR /&gt;&lt;BR /&gt;The method I've heard of before used /etc/profile and a query of where that person was logging in from with probably 'who -a'(?) but I'm concerned this is easy to break (ctrl-\ perhaps?).&lt;BR /&gt;&lt;BR /&gt;I reviewed IPFilter and found that it has no control over specific users as implied by the name.&lt;BR /&gt;&lt;BR /&gt;More to research ...&lt;BR /&gt;&lt;BR /&gt;PK</description>
      <pubDate>Thu, 27 Jan 2005 01:50:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/permit-root-login-through-one-network-nic-only/m-p/3471829#M211905</guid>
      <dc:creator>Philip Kernohan</dc:creator>
      <dc:date>2005-01-27T01:50:10Z</dc:date>
    </item>
  </channel>
</rss>

