Operating System - HP-UX
1819909 Members
2744 Online
109607 Solutions
New Discussion юеВ

Delay in getting login prompt via telnet after inserting tcpd

 
hp_user_1
Regular Advisor

Delay in getting login prompt via telnet after inserting tcpd

Hi All,

As part of server hardening, we recently implemented tcpd on all our hp-ux servers running HP-UX 11iv1. It takes ~40 seconds before we get the telnet prompt. We are experiencing the same delay when we use ftp. Can we fine tune tcpd? We are not using hosts.deny or hosts.allow file.

Any solutions...

Regards,
hp_user
2 REPLIES 2
Steven E. Protter
Exalted Contributor

Re: Delay in getting login prompt via telnet after inserting tcpd

Shalom,

Suggestion:

1) Back out the change on one system and see if the situation improves. If it does you have few options other than perhaps being more selective and using the hosts.deny/hosts.allow files to fine tune.

2) If backing out the change does not help then you may have a host name resolution issue. This can be alieviated by making sure every system has its own hostname and ip address in /etc/hosts. You'd be amazed how many slow login complaints I've resolved over the years with that trick. /etc/nssswitch.conf will have to be checked to make sure it checks files first on host resolution.

SEP
Steven E Protter
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
hp_user_1
Regular Advisor

Re: Delay in getting login prompt via telnet after inserting tcpd

I backed out of the change and here is the result:

1. On PCs it went down from 10 seconds to 2 seconds (as before).

2. On laptops it went down from 40 seconds to 10 seconds (as before).

Our corporate policy is to have tcp wrapper in place for server hardening.

Are there any parameters to tune to reduce the delay while keeping tcpd? Any other workarounds?

Thanks