12.07.2015 Views

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

558APPENDIX DTroubleshootingSecurity TroubleshootingQ. I have stopped all unnecessary services on my servers with external IP addresses andblocked all unnecessary connection requests with IPTables. However, I would like tomonitor which ports are open on each server to make sure someone hasn’t compromisedmy system and opened up ports for other uses. How do I get a list of open ports?A. Use the nmap program. If the system is registered with <strong>Red</strong> <strong>Hat</strong> Network, issue the yuminstall nmap command as root to install it. Then, use execute the nmap command where is the IP address or hostname of the system to scan. Alist of open ports and the service associated with it are listed as in the following:Starting Nmap 4.11 ( http://www.insecure.org/nmap/ ) at 2007-01-21 00:26 ESTInteresting ports on smallville (127.0.0.1):Not shown: 1672 closed portsPORT STATE SERVICE22/tcp open ssh25/tcp open smtp111/tcp open rpcbind139/tcp open netbios-ssn445/tcp open microsoft-ds631/tcp open ipp671/tcp open unknown2049/tcp open nfsQ. I am using the default firewall from the Security Level tool. It is working for meexcept that I need to allow connections for an additional port for the corporateVPN. Can I continue to use the default security level and just add an IPTables rulefor another port?A. Yes. Start the Security Level tool by selecting the System menu from the top paneland then selecting <strong>Administration</strong>, Security Level and Firewall. You can alsoexecute the system-config-securitylevel command to start the tool. At the bottomof the Firewall Options tab, there is an Other ports area. Click the triangle iconbeside the Other ports label to show a table of ports. It should be empty since youhaven’t added any ports yet. Click the Add button to add your additional ports.When finished, click OK in the main window of the tool to enable the change immediately.Execute the iptables -L command to verify that the rule has been added.Q. After modifying the /etc/audit/audit.rules file and restarting the daemon, I getthe following error message:There was an error in line 26 of /etc/audit/audit.rulesWhat does this mean and how do I fix it?A. It means that there is a syntax error on line 26 of the rules file. Re-edit the file to fixthe syntax error, and restart the deamon with the service auditd restartcommand. Then use the auditctl -l command to list all active audit rules andwatches to verify.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!