- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Permit root login through one network (NIC) only
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-26-2005 06:39 AM
01-26-2005 06:39 AM
Permit root login through one network (NIC) only
For example, if my NICs are:
10.26.100.10 and
231.62.100.231
is it possible to permit root access through the 10.X.X.X NIC and *NOT* through the 231.X.X.X NIC?
I know the easiest method is be secure with the root password but allowing access from only within a particular physical environment would make me feel more comfortable.
Any and all help appreciated.
PK
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-26-2005 06:42 AM
01-26-2005 06:42 AM
Re: Permit root login through one network (NIC) only
Else, I can think of ipfilter, tcp wrappers
Anil
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-26-2005 06:43 AM
01-26-2005 06:43 AM
Re: Permit root login through one network (NIC) only
http://software.hp.com/portal/swdepot/displayProductInfo.do?productNumber=B9901AA
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-26-2005 06:52 AM
01-26-2005 06:52 AM
Re: Permit root login through one network (NIC) only
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-26-2005 07:13 AM
01-26-2005 07:13 AM
Re: Permit root login through one network (NIC) only
I'll check out the suggestions and assigns points shortly.
PK
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-26-2005 12:50 PM
01-26-2005 12:50 PM
Re: Permit root login through one network (NIC) only
No, you can't use IPFilter.
IPFilter can only allow/deny access based on IP
address / port #, but it does not have any control
over the user name. For ex, you allow/deny telnet
from 10.26.100.10, you have to allow/deny ALL
users from that machine.
- Biswajit
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-26-2005 03:19 PM
01-26-2005 03:19 PM
Re: Permit root login through one network (NIC) only
You can probably put some code into your /etc/profile that can pick up where the login came from and reject the user. But that will only work for users that have the password.
IPFilter is designed to block ports and protocols, not individual users.
Let me know if you meed monbad and I'll post it somewhere. It is designed for secureshell logins but can easily be upgraded to handle telnet.
Letting root log on with telnet is a bad idea because the password goes through the network in clear text.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-26-2005 05:50 PM
01-26-2005 05:50 PM
Re: Permit root login through one network (NIC) only
I'd be interested in monbad if you can share it?
The method I've heard of before used /etc/profile and a query of where that person was logging in from with probably 'who -a'(?) but I'm concerned this is easy to break (ctrl-\ perhaps?).
I reviewed IPFilter and found that it has no control over specific users as implied by the name.
More to research ...
PK