23.10.2014 Views

Advanced POWER Virtualization on IBM System p5 - Previous ...

Advanced POWER Virtualization on IBM System p5 - Previous ...

Advanced POWER Virtualization on IBM System p5 - Previous ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

The firewall can be switched <strong>on</strong> and off. If enabled with the -<strong>on</strong> switch,<br />

c<strong>on</strong>necti<strong>on</strong>s to the ports ftp-data (20), ftp (21), ssh (22), www (80), https (443),<br />

rmc (657), and cim<strong>on</strong> (32768) will be allowed, all other traffic will be denied.<br />

Example 5-50 shows this procedure.<br />

Example 5-50 Activating the firewall with the viosecure command<br />

$ viosecure -firewall <strong>on</strong><br />

$ viosecure -firewall view<br />

Firewall ON<br />

ALLOWED PORTS<br />

Local Remote<br />

Interface Port Port Service IPAddress Expirati<strong>on</strong><br />

Time(sec<strong>on</strong>ds)<br />

--------- ---- ---- ------- --------- ---------------<br />

$<br />

Further c<strong>on</strong>figurati<strong>on</strong> can allow access to specific ports generally or just for<br />

specified remote machine(s). We show as an example here how to restrict the<br />

rsh command c<strong>on</strong>necti<strong>on</strong>s (Port 112) to a single machine with an IP address of<br />

9.3.5.111. This could well be an administrative machine from which c<strong>on</strong>necti<strong>on</strong>s<br />

to the HMC can be allowed, as the HMC is also able to restrict c<strong>on</strong>necti<strong>on</strong>s to<br />

specified machines (Example 5-51).<br />

Example 5-51 Allowing rsh c<strong>on</strong>necti<strong>on</strong>s from a specified IP address<br />

$ viosecure -firewall allow -port exec -address 9.3.5.111<br />

$ viosecure -firewall view<br />

Firewall ON<br />

ALLOWED PORTS<br />

Local Remote<br />

Interface Port Port Service IPAddress Expirati<strong>on</strong><br />

Time(sec<strong>on</strong>ds)<br />

--------- ---- ---- ------- --------- ---------------<br />

all 512 any exec 9.3.5.111 0<br />

$<br />

The login will now succeed from the IP address 9.3.5.111, while other machines<br />

will not be able to c<strong>on</strong>nect. To deny c<strong>on</strong>necti<strong>on</strong>s to a specified port as well as to<br />

remove the opened port from the firewall list, use the following command<br />

(Example 5-52 <strong>on</strong> page 361).<br />

360 <str<strong>on</strong>g>Advanced</str<strong>on</strong>g> <str<strong>on</strong>g>POWER</str<strong>on</strong>g> <str<strong>on</strong>g>Virtualizati<strong>on</strong></str<strong>on</strong>g> <strong>on</strong> <strong>IBM</strong> <strong>System</strong> <strong>p5</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!