- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- NIC and Bastille problem
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-18-2005 04:03 AM
03-18-2005 04:03 AM
NIC and Bastille problem
Anyone can help me??
Thanks in advanced.
Regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-18-2005 04:15 AM
03-18-2005 04:15 AM
Re: NIC and Bastille problem
Try connecting agan.
If it works, this proves that the setup of the ipfilter firewall is causing the problem.
Then look at the ipf.conf configuration to make changes to allow desired protocols through.
The configuration file is very English language like.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-18-2005 05:39 AM
03-18-2005 05:39 AM
Re: NIC and Bastille problem
> /sbin/init.d/ipfboot stop
> Try connecting agan.
Well, you don't have to go to that extreme :-)
Just run :
# /sbin/ipfstat -ioh
The output would tell you if there are any block rules
configured by IPFilter and if that rule is actually
blocking any traffic. You could post that output here
if you have problem interpreting (with IP addresses
censored, ofcourse).
- Biswajit
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-18-2005 05:43 AM
03-18-2005 05:43 AM
Re: NIC and Bastille problem
Can anyone help me??
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-18-2005 05:56 AM
03-18-2005 05:56 AM
Re: NIC and Bastille problem
AFTER running "/sbin/init.d/ipfboot stop". If that's
what you did, the "ipfstat -ioh" output is useless.
Since you have already unloaded IPFilter, does your
system work fine now?
- Biswajit
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-18-2005 06:03 AM
03-18-2005 06:03 AM
Re: NIC and Bastille problem
The system without the IPFilter service dón´t work.
The Ambiental temperature affect the lan interfaces of the system?? The air conditioned of the lab room its off for ten years
I have two ethernet connections and nothing of these work....
Franci
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-18-2005 06:35 AM
03-18-2005 06:35 AM
Re: NIC and Bastille problem
> The /sbin/ipfstat -ioh run with the IPFilter service
> active.
That's a little odd. Since all the rules (in ipfstat -ioh)
output has 0 at the left, this means IPFilter is not
seeing any traffic (in or out) at all. One thing is clear
though; your problem is not related to IPFilter.
- Biswajit
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-18-2005 09:00 AM
03-18-2005 09:00 AM
Re: NIC and Bastille problem
Anyone can I help to configure bastille??
When I try to configure bastille manually in a text interface, appear a Error associated with "Curses.pm".
Where I can ger this library??
Thanks in advanced...
Francisco
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-18-2005 09:19 AM
03-18-2005 09:19 AM
Re: NIC and Bastille problem
> ..with allow the ports 443/tcp (incoming), 22/tcp
> (incoming), 5555/tcp (incoming), 10000/tcp
> (incoming), 80/tcp (incoming), 20/tcp
> (outcoming), 21/tcp (outcoming), 53/tcp
> (outcoming), 2984/tcp (incoming), 2985/udp
> (incoming) and 514/udp (outcoming)....
Add following rules at the TOP of
/etc/opf/ipf/ipf.conf file:
pass in quick proto tcp from any to any port = 443 flags S keep state keep frags
pass in quick proto tcp from any to any port = 22 flags S keep state keep frags
pass in quick proto tcp from any to any port = 5555 flags S keep state keep frags
pass in quick proto tcp from any to any port = 10000 flags S keep state keep frags
pass in quick proto tcp from any to any port = 80 flags S keep state keep frags
pass out quick proto tcp from any to any port = 20 flags S keep state keep frags
pass out quick proto tcp from any to any port = 21 flags S keep state keep frags
pass out quick proto tcp from any to any port = 53 flags S keep state keep frags
pass in quick proto tcp from any to any port = 2984 flags S keep state keep frags
pass in quick proto udp from any to any port = 2985
pass out quick proto udp from any port = 2985 to any
pass out quick proto udp from any to any port = 514
pass in quick proto udp from any port = 514 to any
WARNING : Test before use. Understand each rule
and make sure that's what you want to do. I have
not tried them, so there might be syntax errors in
them. Each rule should be in one line.
- Biswajit
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-18-2005 09:26 AM
03-18-2005 09:26 AM
Re: NIC and Bastille problem
After you add the above rules to /etc/opt/ipf/ipf.conf
file, reload the IPFilter configuration by executing
following command:
# /sbin/ipf -Fa -f /etc/opt/ipf/ipf.conf
- Biswajit
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-21-2005 04:43 AM
03-21-2005 04:43 AM
Re: NIC and Bastille problem
The best description of the DMZ level is found here:
http://www.docs.hp.com/en/5990-6728/index.html
The ManDMZ level blocks all incoming except for a few protocols, as you saw in your ipfstat -ioh output. If you'd like a level that doesn't block traffic, that's the "host" level.
Re: Curses interface. That is only supported on Linux, not HP-UX. That's why you won't find the library. Bastille uses the X11 GUI, though you can create a configuration on a separate host if you don't can't run an x-window from the locked down system(with --os
Biswajit gave a great rundown on how to add the ports you want to ipfilter. I'd add those to: /etc/opt/sec_mgmt/bastille/ipf.customrules, since that's the file bastille uses to add custom rules to ipfilter's configuration file. That way your ipf.conf changes won't get overwritten the next time you run bastille -b.
As you'd mentioned MANDMZ blocks most inbound ports. I *would* expect you to be able to ssh *from* the locked-down system in all cases.
The one behavior you mentioned that did surprise me was you'd said you can't log in with ssh.
Assuming for the moment that ipfilter and your ssh are running fine, here are the MANDMZ settings that might prevent login (or ftp), depending on security issues present on your system:
# Q: Do not allow logins unless the home directory exists
# Q: Should non-root users be disallowed from logging in if /etc/nologin exists?
# Q: Would you like to disallow ftpd system account logins?
Note that to remove Bastille's configuration automatically, use bastille -r. You can then reapply a configuration or create a custom one. To avoid confusion, we made sure Bastille only tightened a system when "-r" isn't used.
Hope that helped,
-Robert