<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic N-class LAN console security in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/n-class-lan-console-security/m-p/2594653#M755490</link>
    <description>We have an N-class machine which sits outside our internal firewall.  I am using the LAN console, and I would like to connect it to our internal network, so that no-one has access to the console from outside our LAN.&lt;BR /&gt;&lt;BR /&gt;Our network security guy is not happy with this as he just sees the machine as a black box which is connected to both our internal and external networks, and thus gives a hacker the potential to bypass the firewall.&lt;BR /&gt;&lt;BR /&gt;Is it theoretically possible to use the LAN console as a network device in this way?&lt;BR /&gt;I know it doesn't show up as a normal network device to HPUX, but is there any security or architectural documentation I can point to which shows it is not possible?&lt;BR /&gt;&lt;BR /&gt;Oliver.&lt;BR /&gt;</description>
    <pubDate>Mon, 15 Oct 2001 03:13:51 GMT</pubDate>
    <dc:creator>Oliver White</dc:creator>
    <dc:date>2001-10-15T03:13:51Z</dc:date>
    <item>
      <title>N-class LAN console security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/n-class-lan-console-security/m-p/2594653#M755490</link>
      <description>We have an N-class machine which sits outside our internal firewall.  I am using the LAN console, and I would like to connect it to our internal network, so that no-one has access to the console from outside our LAN.&lt;BR /&gt;&lt;BR /&gt;Our network security guy is not happy with this as he just sees the machine as a black box which is connected to both our internal and external networks, and thus gives a hacker the potential to bypass the firewall.&lt;BR /&gt;&lt;BR /&gt;Is it theoretically possible to use the LAN console as a network device in this way?&lt;BR /&gt;I know it doesn't show up as a normal network device to HPUX, but is there any security or architectural documentation I can point to which shows it is not possible?&lt;BR /&gt;&lt;BR /&gt;Oliver.&lt;BR /&gt;</description>
      <pubDate>Mon, 15 Oct 2001 03:13:51 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/n-class-lan-console-security/m-p/2594653#M755490</guid>
      <dc:creator>Oliver White</dc:creator>
      <dc:date>2001-10-15T03:13:51Z</dc:date>
    </item>
    <item>
      <title>Re: N-class LAN console security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/n-class-lan-console-security/m-p/2594654#M755491</link>
      <description>Hi,&lt;BR /&gt;This link may help you &lt;A href="http://forums.itrc.hp.com/cm/QuestionAnswer/1,11866,0x5279abe92dabd5118ff10090279cd0f9,00.html" target="_blank"&gt;http://forums.itrc.hp.com/cm/QuestionAnswer/1,11866,0x5279abe92dabd5118ff10090279cd0f9,00.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Best of luck&lt;BR /&gt;animesh&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 15 Oct 2001 04:14:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/n-class-lan-console-security/m-p/2594654#M755491</guid>
      <dc:creator>Animesh Chakraborty</dc:creator>
      <dc:date>2001-10-15T04:14:59Z</dc:date>
    </item>
    <item>
      <title>Re: N-class LAN console security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/n-class-lan-console-security/m-p/2594655#M755492</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Since the lan console connects to the serial console port of the N and since you plan to have the lan console on an internal (firewalled) network, it seems it should be as secure as having a lan console for a server on the internal network.  Sounds much more secure than having the lan console on the same external net as the N.&lt;BR /&gt;&lt;BR /&gt;Darrell</description>
      <pubDate>Mon, 15 Oct 2001 13:59:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/n-class-lan-console-security/m-p/2594655#M755492</guid>
      <dc:creator>Darrell Allen</dc:creator>
      <dc:date>2001-10-15T13:59:22Z</dc:date>
    </item>
    <item>
      <title>Re: N-class LAN console security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/n-class-lan-console-security/m-p/2594656#M755493</link>
      <description>Oliver,&lt;BR /&gt;&lt;BR /&gt;Find attached the block diagram of the GSP (it's shown as System Access Server (SAS) in the diagram). I hope it helps to calm you network colleague down.&lt;BR /&gt;</description>
      <pubDate>Mon, 15 Oct 2001 14:22:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/n-class-lan-console-security/m-p/2594656#M755493</guid>
      <dc:creator>Patrick Wessel</dc:creator>
      <dc:date>2001-10-15T14:22:28Z</dc:date>
    </item>
    <item>
      <title>Re: N-class LAN console security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/n-class-lan-console-security/m-p/2594657#M755494</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Assuming all your servers has multiple network cards, how about creating a "private network" for all your unix boxes, &lt;BR /&gt;Good luck&lt;BR /&gt;-USA..</description>
      <pubDate>Mon, 15 Oct 2001 14:55:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/n-class-lan-console-security/m-p/2594657#M755494</guid>
      <dc:creator>Uday_S_Ankolekar</dc:creator>
      <dc:date>2001-10-15T14:55:16Z</dc:date>
    </item>
    <item>
      <title>Re: N-class LAN console security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/n-class-lan-console-security/m-p/2594658#M755495</link>
      <description>Thanks for your help so far guys, but I still don't have a clear indication on whether it would be possible to route traffic from a normal network interface through the machine and out over the lan console interface.&lt;BR /&gt;&lt;BR /&gt;ie, could the LAN console be used as a normal network interface&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 15 Oct 2001 23:18:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/n-class-lan-console-security/m-p/2594658#M755495</guid>
      <dc:creator>Oliver White</dc:creator>
      <dc:date>2001-10-15T23:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: N-class LAN console security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/n-class-lan-console-security/m-p/2594659#M755496</link>
      <description>The LAN console is not managed by HP-UX at all, it is run by the Guardian Service Processor. Therefore, you don't see any entry in lanscan or even ioscan.  The only software that knows about it is the GSP.&lt;BR /&gt;&lt;BR /&gt;As mentioned, it is an extension of the RS-232 port, so it behaves just like the console. This means that there is no LAN traffic through the console into HP-UX.  Anything typed at the LAN console goes to the GSP. If you login to the GSP and type the co (console) command, you can get a console prompt. Otherwise, the LAN console has no connection to HP-UX at all...you can only type GSP commands (assuming you can get logged in).&lt;BR /&gt;&lt;BR /&gt;That said, the LAN console (actually GSP) provides far too much information when you first connect, and the default for most N-class GSP's is no user or password...change that before configuring the LAN console.&lt;BR /&gt;&lt;BR /&gt;Since the N-class is outside the firewall, the LAN console should be connected into your corporate network with a private LAN connection, and NOT placed onto the open Internet.  Since the GSP has no network connection to HP-UX, it cannot act as a router or packet forwarder. &lt;BR /&gt;&lt;BR /&gt;So while it would appear that the N-class would have two LAN cards, essentially these are two separate computers which communicate only simple commands between each other via a console connection.  There are no ports open on the LAN console except telnet.</description>
      <pubDate>Tue, 16 Oct 2001 01:04:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/n-class-lan-console-security/m-p/2594659#M755496</guid>
      <dc:creator>Bill Hassell</dc:creator>
      <dc:date>2001-10-16T01:04:53Z</dc:date>
    </item>
  </channel>
</rss>

