23.10.2014 Views

Advanced POWER Virtualization on IBM System p5 - Previous ...

Advanced POWER Virtualization on IBM System p5 - Previous ...

Advanced POWER Virtualization on IBM System p5 - Previous ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

5.7 Security c<strong>on</strong>siderati<strong>on</strong>s for Virtual I/O Servers<br />

The Virtual I/O Server is crucial to the functi<strong>on</strong> of the system. Security is always a<br />

c<strong>on</strong>cern. Although the Virtual I/O Server does not run a lot of services, it has<br />

open ports in the network for c<strong>on</strong>nectivity and users can be created that may<br />

have rights to alter specific system parameters. We will discuss the following<br />

topics here:<br />

► Network security<br />

► <strong>System</strong> parameter security<br />

► Viewing protocol entries related to security<br />

5.7.1 Network security<br />

After installati<strong>on</strong> of the Virtual I/O Server, there is no IP address assigned to <strong>on</strong>e<br />

of the Ethernet interfaces until you c<strong>on</strong>figure it. If that has been d<strong>on</strong>e, by default<br />

there are some services active <strong>on</strong> the system and available from the network that<br />

should be carefully checked. Here is the output of a port scan that took place<br />

after an IP address had been assigned to <strong>on</strong>e of the network interfaces of the<br />

Virtual I/O Server:<br />

ftp<br />

ssh<br />

telnet<br />

rcpbind<br />

RMC c<strong>on</strong>necti<strong>on</strong>s<br />

Ports 20 for data and 21 for c<strong>on</strong>trol c<strong>on</strong>necti<strong>on</strong> allows<br />

unencrypted c<strong>on</strong>necti<strong>on</strong>s to the system; use the scp<br />

command instead.<br />

Port 22 is always encrypted.<br />

Port 23 allows unencrypted c<strong>on</strong>necti<strong>on</strong>s to the system;<br />

use the ssh command instead.<br />

Port 111 is used for NFS c<strong>on</strong>necti<strong>on</strong>s.<br />

Port 657 runs encrypted.<br />

Stopping telnet and ftp services<br />

The ftp and telnet commands can be closed if there are means to c<strong>on</strong>nect to<br />

and exchange data with the Virtual I/O Server via an encrypted protocol. Since<br />

SSH comes preinstalled with the system, we recommend stopping those<br />

services and use SSH instead. To stop the services in the running system as well<br />

as prevent them from starting after a reboot, use the stopnetsvc command.<br />

Example 5-48 <strong>on</strong> page 359 shows how to use it.<br />

358 <str<strong>on</strong>g>Advanced</str<strong>on</strong>g> <str<strong>on</strong>g>POWER</str<strong>on</strong>g> <str<strong>on</strong>g>Virtualizati<strong>on</strong></str<strong>on</strong>g> <strong>on</strong> <strong>IBM</strong> <strong>System</strong> <strong>p5</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!