23.10.2014 Views

Advanced POWER Virtualization on IBM System p5 - Previous ...

Advanced POWER Virtualization on IBM System p5 - Previous ...

Advanced POWER Virtualization on IBM System p5 - Previous ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Example 5-52 Denying rsh c<strong>on</strong>necti<strong>on</strong>s from a specified IP address<br />

$ viosecure -firewall deny -port exec -address 9.3.5.111<br />

$ viosecure -firewall view<br />

Firewall ON<br />

ALLOWED PORTS<br />

Local Remote<br />

Interface Port Port Service IPAddress Expirati<strong>on</strong><br />

Time(sec<strong>on</strong>ds)<br />

--------- ---- ---- ------- --------- ---------------<br />

$<br />

All firewall settings will be recorded to the file viosfirewall.rules in the home<br />

directory of the padmin user up<strong>on</strong> firewall shutdown with the viosecure<br />

-firewall off command. However, the padmin user is not allowed to see the<br />

c<strong>on</strong>tents. Up<strong>on</strong> startup of the firewall, the settings of the file viosfirewall.rules will<br />

be applied to the firewall again so that no modificati<strong>on</strong>s are lost.<br />

<strong>System</strong> parameter security<br />

Some system parameters require careful c<strong>on</strong>siderati<strong>on</strong> if higher security levels<br />

are required. These can be user parameters as well as network parameters. The<br />

viosecure command as of Virtual I/O Server Versi<strong>on</strong> 1.3 supports changes to 37<br />

parameters. The output of the viosecure -n<strong>on</strong>int -view command shows the<br />

parameters that can be set:<br />

$viosecure -n<strong>on</strong>int -view<br />

Enable telnet (telnetdls):Uncomments the entry for telnetd daem<strong>on</strong> in<br />

/etc/inetd.c<strong>on</strong>f and starts telnetd daem<strong>on</strong>.<br />

Disable UDP chargen service in /etc/inetd.c<strong>on</strong>f (udpchargendls):comments<br />

the entry for UDP Chargen service in /etc/inetd.c<strong>on</strong>f and kills all<br />

instances of chargen.<br />

Disable sprayd in /etc/inetd.c<strong>on</strong>f (sprayddls):comments the entry for<br />

sprayd daem<strong>on</strong> in /etc/inetd.c<strong>on</strong>f and kills all instances of sprayd.<br />

Minimum number of chars (mindiffdls):Removes the c<strong>on</strong>straint <strong>on</strong> the<br />

minimum number of characters required in a new password that were not<br />

in the old password.<br />

Set core file size (coredls):Remove the core attribute for root.<br />

Password expirati<strong>on</strong> warning time (pwdwarntimedls):Removes the<br />

c<strong>on</strong>straint <strong>on</strong> the number of days before the system issues a warning<br />

that a password change is required.<br />

Disable dtspc in /etc/inetd.c<strong>on</strong>f (dtspcdls):comments the entry for<br />

dtspc daem<strong>on</strong> in /etc/inetd.c<strong>on</strong>f when LFT is not c<strong>on</strong>figured and CDE is<br />

disabled in /etc/inittab, also kills all the instances of dtspc daem<strong>on</strong>.<br />

Chapter 5. <strong>System</strong> management 361

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!