- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- GSP Securitcy Issues?
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-12-2003 04:46 AM
05-12-2003 04:46 AM
GSP Securitcy Issues?
We are getting ready to upgrade from 8 k580's to 20+ 7400's and I'm trying to figure out how to arrange the terminal connections. Previously, I have had an 8 port serial switch connected to a dumb terminal. Now I'm looking at creating a standalone network for the GSPs. I'm having problems talking my security folks into it as the networks these guys are on are seperated and they are worried about a bad guy being able to bypass the firewall via the gsp cards. Anyone have any security whitepapers on these or even a better recommendation?
Thanks,
Eric
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-12-2003 05:27 AM
05-12-2003 05:27 AM
Re: GSP Securitcy Issues?
Put your gsp network behind the firewall - far safer.
Paula
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-12-2003 05:51 AM
05-12-2003 05:51 AM
Re: GSP Securitcy Issues?
An 'administrative' account and password exists for the RP7400's GSP, along with user accounts with restricted privileges, and while these accounts can remain separate from the 'root' account of the actual server they are rarely used except with vpars or npars. For example there can be an administrative GSP 'user 1' with full access and 'user 2' through 'user 20' with restricted command sets. Give read only access to user's 2 and beyond and keep user 1 to yourself and set up with update permission.
The stand alone network is the way to go. Put your LAN consoles on a separate switch, especially if you have DMZ's or publicly facing servers. You'll find you have no choice with this configuration.
You can also hide the IP addresses of the Secure Console devices by not listing them in /etc/hosts but this is sometimes a tough call since the IP now takes on the form of a password which is being kept secret.
Also, your LAN console access is often at 10BaseT instead of 100 so bear this in mind when connecting to your switch. (* Use 'linkloop MAC'. *)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-12-2003 07:36 AM
05-12-2003 07:36 AM
Re: GSP Securitcy Issues?
We used to have all our SWC's on public, (as well as the MP lans...) and a few months ago that subnet started getting scanned. For some reason the nature of the scanning took all the SWC's down. (We also had Compaq light's out cards on that subnet. I blame them for the scanning... ;) ) This happened for about 3 weeks until I had time to figure out what was really happening. Since moving to private addressing, we have not had a single issue with the GSP ports or the swc's. (And I don't expect to.)
As far as access goes, I can still get to them from anywhere through the corporate VPN. I assume your security guys provide you with VPN access, right?
Hope it helps
John
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-12-2003 08:27 AM
05-12-2003 08:27 AM
Re: GSP Securitcy Issues?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-12-2003 09:34 AM
05-12-2003 09:34 AM
Re: GSP Securitcy Issues?
Bill Hassell, sysadmin