04.06.2013 Views

UCS 2.4 - Univention

UCS 2.4 - Univention

UCS 2.4 - Univention

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

10.3 Packet filter with <strong>Univention</strong> Firewall<br />

10.3 Packet filter with <strong>Univention</strong> Firewall<br />

<strong>Univention</strong> Firewall offers an integration of the packet filter IPTables into <strong>Univention</strong> Corporate Server. This<br />

filter permits targeted filtering of undesired services, and the protection of computers during installation<br />

works. Furthermore it provides the basis for complex scenarios such as firewalls and Application Level<br />

Gateways. <strong>Univention</strong> Firewall is included in all <strong>Univention</strong> Corporate Server installations as a standard<br />

feature.<br />

The configuration for the packet filter can be found in the directory /etc/security/netfilter.d/.<br />

The configuration elements available in this directory, are executed in alphabetical order. The name of<br />

each script begins with two digits, which makes it easy to create a numbered order.<br />

After changing the packet filter settings, the service univention-iptables has to be restarted.<br />

<strong>Univention</strong> Firewall can be deactivated by setting the <strong>Univention</strong> Configuration Registry variable<br />

security/packetfilter/disabled to true.<br />

10.3.1 Service definitions<br />

<strong>Univention</strong> Firewall allows selective filtering of individual services by <strong>Univention</strong> Configuration Registry, for<br />

example if a service is temporarily not required or to be deactivated for test purposes. At present, the<br />

following services are supported in <strong>UCS</strong>:<br />

smtp pop3 imap kerberos<br />

krsh nfs umc nagios<br />

ipp notifier dhcp dns<br />

ftp http x11 https<br />

ldap postgres samba ssh<br />

telnet ftp<br />

If the <strong>Univention</strong> Configuration Registry variable security/services/SERVICE is set to disabled, the cor-<br />

responding service is filtered out.<br />

Attention:<br />

These services are filtered by means of their default ports. If a service is operated at a different port, then<br />

the corresponding <strong>Univention</strong> Configuration Registry template has to be adapted.<br />

10.3.2 Service profiles<br />

<strong>Univention</strong> Firewall supports pre-defined service profiles for each system role. The services to be filtered<br />

out, are defined for each role in the above-mentioned <strong>Univention</strong> Configuration Registry settings.<br />

Attention:<br />

It has to be considered that it is merely a selective filter which is used here. If additional local services are<br />

applied, they have to be registered subsequently.<br />

223

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!