<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: All telnet sessions tagged as intruder in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/all-telnet-sessions-tagged-as-intruder/m-p/5178376#M30479</link>
    <description>You said this is your new BL860c, which makes me ask:&lt;BR /&gt;1: Has this ever worked?&lt;BR /&gt;2: If the first answer is yes, what have you changed lately?</description>
    <pubDate>Fri, 29 May 2009 17:48:40 GMT</pubDate>
    <dc:creator>Mike Smith_33</dc:creator>
    <dc:date>2009-05-29T17:48:40Z</dc:date>
    <item>
      <title>All telnet sessions tagged as intruder</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/all-telnet-sessions-tagged-as-intruder/m-p/5178375#M30478</link>
      <description>&lt;!--!*#--&gt;I'm looking at in issue on my new BL860c running 8.3-1H1 and Multinet 5.2.  OS and Multinet are at current patch levels.  As shown below on a SHOW INTRUSION, the SOURCE is showing that records are from a telnet source, but the HEX IP address/port into is missing.  Therefore EVERY failed telnet session appears to be from the same source and when classified as in Intruder, nobody can start in inbound telnet session from ANY terminal.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;CYRUS&amp;gt; sho intru&lt;BR /&gt;Intrusion       Type       Count        Expiration         Source&lt;BR /&gt;---------       ----       -----        ----------         ------&lt;BR /&gt;   NETWORK      SUSPECT      32   29-MAY-2009 12:31:05.20  TELNET::&lt;UNKNOWN&gt;&lt;BR /&gt;&lt;BR /&gt;I'm expecting something more like this:&lt;BR /&gt;Intrusion       Type       Count        Expiration         Source&lt;BR /&gt;---------       ----       -----        ----------         ------&lt;BR /&gt;   NETWORK      SUSPECT       5   29-MAY-2009 12:36:44.78  TELNET::7F000001&lt;BR /&gt;&lt;BR /&gt;I'm just looking to see if anybody else has run across this particular behavior before opening support tickets.  I'm reviewing all of my Multinet information to see if the problem is on that portion.  Just to keep people working, I've reduced the LGI_HID_TIM parameter to zero so nobody gets locked out, but I of course don't want to leave that setting as-is for too long even on this non-internet facing system.&lt;/UNKNOWN&gt;</description>
      <pubDate>Fri, 29 May 2009 16:18:18 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/all-telnet-sessions-tagged-as-intruder/m-p/5178375#M30478</guid>
      <dc:creator>Sloan Essman</dc:creator>
      <dc:date>2009-05-29T16:18:18Z</dc:date>
    </item>
    <item>
      <title>Re: All telnet sessions tagged as intruder</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/all-telnet-sessions-tagged-as-intruder/m-p/5178376#M30479</link>
      <description>You said this is your new BL860c, which makes me ask:&lt;BR /&gt;1: Has this ever worked?&lt;BR /&gt;2: If the first answer is yes, what have you changed lately?</description>
      <pubDate>Fri, 29 May 2009 17:48:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/all-telnet-sessions-tagged-as-intruder/m-p/5178376#M30479</guid>
      <dc:creator>Mike Smith_33</dc:creator>
      <dc:date>2009-05-29T17:48:40Z</dc:date>
    </item>
    <item>
      <title>Re: All telnet sessions tagged as intruder</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/all-telnet-sessions-tagged-as-intruder/m-p/5178377#M30480</link>
      <description>Has never worked properly on this system (nor my other 3 bl860c's)  All have the same OS and Multinet.  It's worked on every other system I've had, including my main production system, an ES40 with 7.3-2 and Multinet 4.4.</description>
      <pubDate>Fri, 29 May 2009 17:53:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/all-telnet-sessions-tagged-as-intruder/m-p/5178377#M30480</guid>
      <dc:creator>Sloan Essman</dc:creator>
      <dc:date>2009-05-29T17:53:40Z</dc:date>
    </item>
    <item>
      <title>Re: All telnet sessions tagged as intruder</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/all-telnet-sessions-tagged-as-intruder/m-p/5178378#M30481</link>
      <description>Check for the available MultiNet ECO and apply; most any support call is going to ask you to get current, regardless.   Here, the MASTER_SERVER-053_A052 kit:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.multinet.process.com/scripts/eco/eco_tlb.com?MASTER_SERVER-053_A052" target="_blank"&gt;http://www.multinet.process.com/scripts/eco/eco_tlb.com?MASTER_SERVER-053_A052&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Has a fix for something that looks very similar to this reported case.&lt;BR /&gt;&lt;BR /&gt;"- Handle mapped IPv4 addresses correctly when doing accounting so that VMS intrusion handling continues to work as it did in prior versions of MultiNet. Note that this does not address the issue for IPv6 addresses that are not IPv4 mapped addresses; support for that will require a MultiNet Kernel patch.  (DE 10517 ECO MASTER_SERVER-020_A052 ECO Rank 3."</description>
      <pubDate>Fri, 29 May 2009 18:18:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/all-telnet-sessions-tagged-as-intruder/m-p/5178378#M30481</guid>
      <dc:creator>Hoff</dc:creator>
      <dc:date>2009-05-29T18:18:49Z</dc:date>
    </item>
    <item>
      <title>Re: All telnet sessions tagged as intruder</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/all-telnet-sessions-tagged-as-intruder/m-p/5178379#M30482</link>
      <description>Hoff's answer should be the fix.  TELNET was moved to IPv6 with MultiNet 5.2 and there were some errors in processing how addresses are handled in a few places.&lt;BR /&gt;&lt;BR /&gt;If you are up to date on the patches, then try changing the socket-family for telnet to AF_INET:&lt;BR /&gt;&lt;BR /&gt;$ multinet configure/server&lt;BR /&gt;SERVER-CONFIG&amp;gt;select telnet&lt;BR /&gt;SERVER-CONFIG&amp;gt;set socket-family AF_INET&lt;BR /&gt;SERVER-CONFIG&amp;gt;write&lt;BR /&gt;SERVER-CONFIG&amp;gt;exit&lt;BR /&gt;$ @multinet:start_Server restart</description>
      <pubDate>Fri, 29 May 2009 18:38:48 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/all-telnet-sessions-tagged-as-intruder/m-p/5178379#M30482</guid>
      <dc:creator>Richard Whalen</dc:creator>
      <dc:date>2009-05-29T18:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: All telnet sessions tagged as intruder</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/all-telnet-sessions-tagged-as-intruder/m-p/5178380#M30483</link>
      <description>I think that patch will be it too.  I'm downloading it now.  When I patched Multinet, I just grabbed everything off their "recommended" list.  I didn't think to go read through the rest.&lt;BR /&gt;&lt;BR /&gt;I have a system that's still in staging so I can tweak it at will.  I'll post an update after applying the patch to that system and testing (along with the other 15 things going on today)!</description>
      <pubDate>Fri, 29 May 2009 18:42:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/all-telnet-sessions-tagged-as-intruder/m-p/5178380#M30483</guid>
      <dc:creator>Sloan Essman</dc:creator>
      <dc:date>2009-05-29T18:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: All telnet sessions tagged as intruder</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/all-telnet-sessions-tagged-as-intruder/m-p/5178381#M30484</link>
      <description>That was it Hoff.  Intrusion records are displaying properly now on the system that I updated.  I'll update my other systems and get intrusion protection working properly.&lt;BR /&gt;&lt;BR /&gt;Thanks for the 2nd set of eyes.  I REALLY suspected it was a behavior change in Multinet but just hadn't tracked it down yet.  You saved me some time.&lt;BR /&gt;&lt;BR /&gt;Thanks to everybody for the input!</description>
      <pubDate>Fri, 29 May 2009 18:50:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/all-telnet-sessions-tagged-as-intruder/m-p/5178381#M30484</guid>
      <dc:creator>Sloan Essman</dc:creator>
      <dc:date>2009-05-29T18:50:03Z</dc:date>
    </item>
  </channel>
</rss>

