Operating System - HP-UX
1847870 Members
3423 Online
104021 Solutions
New Discussion

Want to be able to restrict TELNET based on IP subnet...HP UX 11i

 
John O'Neill_6
Regular Advisor

Want to be able to restrict TELNET based on IP subnet...HP UX 11i

Hi All,

I was wondering if the following is possible...

I'm running HP UX 11i
Our Applications are PROGRESS based and
are character mode applications run via TELNET.

I want to be able to have incomming TELNET's for a given user ID bound to a particular subnet or network adapter, or range of IP addresses.

IE, allow telnet from addresses
192.168.0.

disallow telnet from addresses
192.168.1.

This is because I have a bunch of IP clients that need to use one user ID and a bunch that need to user another user ID, it's all a bit ugly but that's what I might have to deal with.

Can a users .profile script or a user profile in HP UX be set in such a way as to block TELNET based on where the incomming TELNET is comming from?

-John
6 REPLIES 6
Uday_S_Ankolekar
Honored Contributor

Re: Want to be able to restrict TELNET based on IP subnet...HP UX 11i

You can control this from /var/adm/inetd.sec file.

man inetd.sec for more info..

-USA..
Good Luck..
Victor BERRIDGE
Honored Contributor

Re: Want to be able to restrict TELNET based on IP subnet...HP UX 11i

Hi John,This could be done by adding security to the inetd daemon, you will have to configure /var/adm/inetd.sec file.See the inetd.sec (4) man pageAll the bestVictor
Steven E. Protter
Exalted Contributor

Re: Want to be able to restrict TELNET based on IP subnet...HP UX 11i

Contentes of entry

telnetd allow 192.168.0.*
telnetd deny 192.168.1.*

It might just be telnet. I don't remember.

SEP
Steven E Protter
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
John O'Neill_6
Regular Advisor

Re: Want to be able to restrict TELNET based on IP subnet...HP UX 11i

Hi Everyone, thanks heaps.

Points allocated :)

-John
Emil Velez
Honored Contributor

Re: Want to be able to restrict TELNET based on IP subnet...HP UX 11i

John

You can also allow and deny based on userid too. There is a package called tcpwrapper that allows reverse name resolution, and allows allow and deny capability based on userid and hostname.

You may also want to look at that as a feature. You can download it from http://software.hp.com select security.

Emil
Jakes Louw
Trusted Contributor

Re: Want to be able to restrict TELNET based on IP subnet...HP UX 11i

If the TCPWrapper is the one from Wiets Vennema University, then it has a limitation on the number of entries (IP addresses or names) that it can track. Unless of course this was solved in later versions.....
Stick with inetd.sec, at least you can complain to HP if it doesn't work....;->
Trying is the first step to failure - Homer Simpson