- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Bastille Setup
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-29-2004 12:59 AM
тАО10-29-2004 12:59 AM
Is there any way to do this via command line ?
# perl D.5.8.0.B Perl Programming Language
perl.Perl5 D.5.8.0.B Perl for HP-UX
# Bastille B.02.01.01 HP-UX Security Hardening Tool
Bastille.BASTILLE B.02.01.01 HP-UX Security Hardening Tool
Solved! Go to Solution.
- Tags:
- bastille
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-29-2004 01:06 AM
тАО10-29-2004 01:06 AM
Re: Bastille Setup
It says so in the documentation.
I would suggest you configure a laptop with X emulation and plug it into the DMZ. If the HP-9000 server has a graphics card and monitor, you can run cde at the console and do it right on the server.
Alternatively, you can have the necessary ports openned on the firewall only to and from the IP address you normally run your X emmulation software on.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-29-2004 01:16 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-29-2004 01:41 AM
тАО10-29-2004 01:41 AM
Re: Bastille Setup
If so then you can configure ssh to tunnel the X-windows traffic back to your local X workstation.
Assuming your web server is not running an X server, the following procedure will work.
From the X Workstation: -
xhost +
ssh webserver1 -R 6000:localhost:6000
(authenticate yourself)
export DISPLAY=localhost:0
bastille
This will setup a tunnel, via your ssh connection, that will redirect all port 6000 traffic on the webserver to port 6000 on your workstation. Therefore DISPLAY=localhost:0 indirectly sends the X traffic to your workstation.
If the web server already uses port 6000 for an XWindows head, you can use a different port, eg: -
ssh webserver1 -R 6001:localhost:6000
(authenticate)
export DISPLAY=localhost:1
etc.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-01-2004 05:12 AM
тАО11-01-2004 05:12 AM
Re: Bastille Setup
1. X11Forwarding is recommended if you want to run the GUI on a remote server.
ssh -X root@server
2. The --os option may be used to create a "full" config for a given OS. This lessens the need to have a "similar" non-DMZ server, and you can copy the config out there and apply it with bastille -b. Although the Linux package is not supported by HP, this option can even be used on Linux to create an HP-UX config that can then be
copied over to your server.
3. It is possible to tweak the config manually using an editor. However, I highly recommend creating your first config with the GUI. The explanations of the question are intended to be educational and help you understand the tradeoffs that you are making.
Check out
/opt/sec_mgmt/bastille/docs/user_guide.txt
for some more details.
Hope that helps.
-Keith
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-02-2004 02:42 AM
тАО11-02-2004 02:42 AM