<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TCPIP port security (IP blacklist) in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/tcpip-port-security-ip-blacklist/m-p/4463740#M30812</link>
    <description>hi,&lt;BR /&gt;&lt;BR /&gt; stevens post still stands :-&lt;BR /&gt;&lt;BR /&gt;tcpip&amp;gt; set service &lt;SERV name=""&gt; /reject=host=&lt;IP address=""&gt;&lt;BR /&gt;&lt;BR /&gt;tcpip&amp;gt; disab serv &lt;SERV name=""&gt;&lt;BR /&gt;&lt;BR /&gt;tcpip &amp;gt; enab serv &lt;SERV name=""&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;fwiw&lt;BR /&gt;&lt;BR /&gt;&lt;/SERV&gt;&lt;/SERV&gt;&lt;/IP&gt;&lt;/SERV&gt;</description>
    <pubDate>Tue, 21 Jul 2009 13:17:41 GMT</pubDate>
    <dc:creator>marsh_1</dc:creator>
    <dc:date>2009-07-21T13:17:41Z</dc:date>
    <item>
      <title>TCPIP port security (IP blacklist)</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/tcpip-port-security-ip-blacklist/m-p/4463736#M30808</link>
      <description>Hello.&lt;BR /&gt; &lt;BR /&gt;Is there a way to defined (somewhere in TCPIP configuration) some IP address, which will not have access to specific port on OpenVMS? So far I didn't find anything. Thanks in advance.</description>
      <pubDate>Tue, 21 Jul 2009 12:29:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/tcpip-port-security-ip-blacklist/m-p/4463736#M30808</guid>
      <dc:creator>Dolezel Vaclav</dc:creator>
      <dc:date>2009-07-21T12:29:43Z</dc:date>
    </item>
    <item>
      <title>Re: TCPIP port security (IP blacklist)</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/tcpip-port-security-ip-blacklist/m-p/4463737#M30809</link>
      <description>does tcpip &amp;gt; set communication /reject=() meet your requirements ?</description>
      <pubDate>Tue, 21 Jul 2009 12:42:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/tcpip-port-security-ip-blacklist/m-p/4463737#M30809</guid>
      <dc:creator>Ananth S</dc:creator>
      <dc:date>2009-07-21T12:42:39Z</dc:date>
    </item>
    <item>
      <title>Re: TCPIP port security (IP blacklist)</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/tcpip-port-security-ip-blacklist/m-p/4463738#M30810</link>
      <description>&lt;!--!*#--&gt;&amp;gt; [...] to specific port [...]&lt;BR /&gt;&lt;BR /&gt;TCPIP HELP SET SERVICE /REJECT&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;As usual, output from "TCPIP SHOW VERSION"&lt;BR /&gt;might be helpful.</description>
      <pubDate>Tue, 21 Jul 2009 12:45:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/tcpip-port-security-ip-blacklist/m-p/4463738#M30810</guid>
      <dc:creator>Steven Schweda</dc:creator>
      <dc:date>2009-07-21T12:45:42Z</dc:date>
    </item>
    <item>
      <title>Re: TCPIP port security (IP blacklist)</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/tcpip-port-security-ip-blacklist/m-p/4463739#M30811</link>
      <description>HP TCP/IP Services for OpenVMS Alpha Version V5.4 - ECO 6&lt;BR /&gt;  on a COMPAQ AlphaServer DS20E 833 MHz running OpenVMS V7.3-2&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 21 Jul 2009 13:04:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/tcpip-port-security-ip-blacklist/m-p/4463739#M30811</guid>
      <dc:creator>Dolezel Vaclav</dc:creator>
      <dc:date>2009-07-21T13:04:29Z</dc:date>
    </item>
    <item>
      <title>Re: TCPIP port security (IP blacklist)</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/tcpip-port-security-ip-blacklist/m-p/4463740#M30812</link>
      <description>hi,&lt;BR /&gt;&lt;BR /&gt; stevens post still stands :-&lt;BR /&gt;&lt;BR /&gt;tcpip&amp;gt; set service &lt;SERV name=""&gt; /reject=host=&lt;IP address=""&gt;&lt;BR /&gt;&lt;BR /&gt;tcpip&amp;gt; disab serv &lt;SERV name=""&gt;&lt;BR /&gt;&lt;BR /&gt;tcpip &amp;gt; enab serv &lt;SERV name=""&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;fwiw&lt;BR /&gt;&lt;BR /&gt;&lt;/SERV&gt;&lt;/SERV&gt;&lt;/IP&gt;&lt;/SERV&gt;</description>
      <pubDate>Tue, 21 Jul 2009 13:17:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/tcpip-port-security-ip-blacklist/m-p/4463740#M30812</guid>
      <dc:creator>marsh_1</dc:creator>
      <dc:date>2009-07-21T13:17:41Z</dc:date>
    </item>
    <item>
      <title>Re: TCPIP port security (IP blacklist)</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/tcpip-port-security-ip-blacklist/m-p/4463741#M30813</link>
      <description>&lt;!--!*#--&gt;And "ECO 7" is available, too (but I doubt&lt;BR /&gt;that it would make any difference on this&lt;BR /&gt;question).</description>
      <pubDate>Tue, 21 Jul 2009 13:25:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/tcpip-port-security-ip-blacklist/m-p/4463741#M30813</guid>
      <dc:creator>Steven Schweda</dc:creator>
      <dc:date>2009-07-21T13:25:14Z</dc:date>
    </item>
    <item>
      <title>Re: TCPIP port security (IP blacklist)</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/tcpip-port-security-ip-blacklist/m-p/4463742#M30814</link>
      <description>Blocking IP subnet ranges?  &lt;BR /&gt;&lt;BR /&gt;No available TCP/IP Services software release for OpenVMS provides that capability.  &lt;BR /&gt;&lt;BR /&gt;OpenVMS V8.4 might change that, according to the last roadmap I checked; there was a firewall planned for that release.  (Though the UI and the capabilities of that software firewall have not AFAIK been disclosed yet.)&lt;BR /&gt;&lt;BR /&gt;In general, I prefer to use an external firewall with OpenVMS when connecting to an untrusted network.&lt;BR /&gt;&lt;BR /&gt;Depending on the network traffic load involved with this OpenVMS box, these firewall boxes can be quite inexpensive and very effective.&lt;BR /&gt;&lt;BR /&gt;And even a low-end firewall can easily block the problem CIDR ranges.  &lt;BR /&gt;&lt;BR /&gt;(The next "wrinkle" here tends to be the lack of a syslogd on OpenVMS, but that can be addressed in various ways.  OpenVMS can be integrated with a syslog-based network, but it requires adding syslog client or syslogd daemon software to OpenVMS.)</description>
      <pubDate>Tue, 21 Jul 2009 13:37:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/tcpip-port-security-ip-blacklist/m-p/4463742#M30814</guid>
      <dc:creator>Hoff</dc:creator>
      <dc:date>2009-07-21T13:37:32Z</dc:date>
    </item>
    <item>
      <title>Re: TCPIP port security (IP blacklist)</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/tcpip-port-security-ip-blacklist/m-p/4463743#M30815</link>
      <description>&lt;!--!*#--&gt;&amp;gt; Blocking IP subnet ranges?&lt;BR /&gt;&amp;gt;&lt;BR /&gt;&amp;gt; No available TCP/IP Services software&lt;BR /&gt;&amp;gt; release for OpenVMS provides that&lt;BR /&gt;&amp;gt; capability.&lt;BR /&gt;&lt;BR /&gt;Hmmm.  That's exactly how I would have&lt;BR /&gt;described&lt;BR /&gt;&lt;BR /&gt;TCPIP SET SERVICE /REJECT = NETWORKS = [...]&lt;BR /&gt;&lt;BR /&gt;    For each network, you can optionally specify&lt;BR /&gt;    the network mask. The default net mask equals&lt;BR /&gt;    network's class number. For example, for&lt;BR /&gt;    network 11.200.0.0., the default mask is&lt;BR /&gt;    255.0.0.0.&lt;BR /&gt;&lt;BR /&gt;Dosn't that qualify as some kind of IP subnet&lt;BR /&gt;range?&lt;BR /&gt;&lt;BR /&gt;Of course,&lt;BR /&gt;    Maximum is 16.&lt;BR /&gt;can be rather limiting.</description>
      <pubDate>Tue, 21 Jul 2009 13:48:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/tcpip-port-security-ip-blacklist/m-p/4463743#M30815</guid>
      <dc:creator>Steven Schweda</dc:creator>
      <dc:date>2009-07-21T13:48:27Z</dc:date>
    </item>
    <item>
      <title>Re: TCPIP port security (IP blacklist)</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/tcpip-port-security-ip-blacklist/m-p/4463744#M30816</link>
      <description>OpenVMS does not offer an IP firewall.&lt;BR /&gt;&lt;BR /&gt;Work for a while with ipfw or ipchains or a comparable-recent host-based firewall, or work with an external commercial mid-grade server firewall or a dual-NIC x86 open-source firewall (eg: m0n0wall or smoothwall), and call me back.  &lt;BR /&gt;&lt;BR /&gt;With most any of those solutions, hundreds or thousands of CIDR-based port-range blocks are trivial.  Far more important (as you get into this stuff) are the adaptive firewall blocks; whether based on Spamhaus Zen DNSBL or otherwise.  Static CIDR blocks aren't a practical solution with IPv4, much less with IPv6.&lt;BR /&gt;&lt;BR /&gt;I do hope that the host-based firewall from the V8.4 roadmap is at least as capable as the ipchains firewall.   That is, that the new firewall will have capabilities commensurate with the typical value of a target box running OpenVMS.&lt;BR /&gt;</description>
      <pubDate>Tue, 21 Jul 2009 14:34:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/tcpip-port-security-ip-blacklist/m-p/4463744#M30816</guid>
      <dc:creator>Hoff</dc:creator>
      <dc:date>2009-07-21T14:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: TCPIP port security (IP blacklist)</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/tcpip-port-security-ip-blacklist/m-p/4463745#M30817</link>
      <description>Hi Steve,&lt;BR /&gt;&lt;BR /&gt;&amp;gt; OpenVMS does not offer an IP firewall.&lt;BR /&gt;&lt;BR /&gt;Really?&lt;BR /&gt;&lt;BR /&gt;This is what I have/had from one of the guys that wrote it: -&lt;BR /&gt;&lt;BR /&gt;&amp;gt; BTW, delivery of IPSEC also provides &lt;BR /&gt;&amp;gt; host-based firewall capability, which &lt;BR /&gt;&amp;gt; is another important feature that would&lt;BR /&gt;&amp;gt;  also be delayed if IPSEC is further&lt;BR /&gt;&amp;gt; delayed.&lt;BR /&gt;&lt;BR /&gt;Are you now seperating (for the customer delivery expectations) IPsec and VMS firewall capabilities?&lt;BR /&gt;&lt;BR /&gt;&amp;gt; I do hope that the host-based firewall&lt;BR /&gt;&amp;gt; from the V8.4 roadmap is at least as&lt;BR /&gt;&amp;gt; capable as the ipchains firewall.&lt;BR /&gt;&lt;BR /&gt;Which V8.4 roadmap are you talking about???&lt;BR /&gt;&lt;BR /&gt;IPsec and VMS firewall functionality were (after several prominant years) erased from the 8.4 (after the 8.3 :-( ) roadmap at the mere stroke of the pen. What say you now?&lt;BR /&gt;&lt;BR /&gt;Cheers Richard Maher&lt;BR /&gt; &lt;BR /&gt;</description>
      <pubDate>Wed, 22 Jul 2009 10:59:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/tcpip-port-security-ip-blacklist/m-p/4463745#M30817</guid>
      <dc:creator>Richard J Maher</dc:creator>
      <dc:date>2009-07-22T10:59:28Z</dc:date>
    </item>
    <item>
      <title>Re: TCPIP port security (IP blacklist)</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/tcpip-port-security-ip-blacklist/m-p/4463746#M30818</link>
      <description>Thanks for the update.  I hadn't noticed that the firewall feature was dropped from the V8.4 roadmap.  Ah, well.&lt;BR /&gt;&lt;BR /&gt;I'd not been waiting for V8.4 here regardless, and am presently running external firewall boxes for the OpenVMS servers both for the direct control and for various other capabilities that a firewall can provide.</description>
      <pubDate>Wed, 22 Jul 2009 11:26:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/tcpip-port-security-ip-blacklist/m-p/4463746#M30818</guid>
      <dc:creator>Hoff</dc:creator>
      <dc:date>2009-07-22T11:26:56Z</dc:date>
    </item>
    <item>
      <title>Re: TCPIP port security (IP blacklist)</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/tcpip-port-security-ip-blacklist/m-p/4463747#M30819</link>
      <description>Waiting for the update, if the need for blocking a specific port is really important, you can do it the "dirty way": implement in sylogin a procedure to lookup the BG device of the incoming connections, harvest the local or remote tcpip port from output of tcpip sho dev and logout the "hacker".&lt;BR /&gt;Or I can do it for you for 5 czech beers :)</description>
      <pubDate>Thu, 30 Jul 2009 17:49:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/tcpip-port-security-ip-blacklist/m-p/4463747#M30819</guid>
      <dc:creator>cdan</dc:creator>
      <dc:date>2009-07-30T17:49:07Z</dc:date>
    </item>
    <item>
      <title>Re: TCPIP port security (IP blacklist)</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/tcpip-port-security-ip-blacklist/m-p/5379607#M30820</link>
      <description>&lt;P&gt;System Detective, which I develop at PointSecure, has the capability, among many others, of deleting processes with a specific string in the port field of their terminal.&amp;nbsp; The source of a session connection&amp;nbsp;is frequently listed in the port field.&amp;nbsp; Security events are recorded, notifications may be made, reports may be generated, etc.&amp;nbsp; You can see information about System Detective at &lt;A target="_blank" href="http://www.PointSecure.com."&gt;www.PointSecure.com.&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2011 15:03:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/tcpip-port-security-ip-blacklist/m-p/5379607#M30820</guid>
      <dc:creator>Warren_Kahle</dc:creator>
      <dc:date>2011-11-02T15:03:11Z</dc:date>
    </item>
  </channel>
</rss>

