Cabletron Systems E2100 Especificaciones

Busca en linea o descarga Especificaciones para Redes Cabletron Systems E2100. Cabletron Systems E2100 Specifications Manual de usuario

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 233
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente

Indice de contenidos

Pagina 1 - FirewallonCD2

SuSELinuxFirewallonCD2

Pagina 3 - Contents

Figure 3.47: Destination NAT for VPN ConnectionsPage 1/2 IPSec VPN TunnelFirst, the certificate for Nuremberg is selected. To do this, click ‘Select Ce

Pagina 4

3Firewall Administration System (FAS)The Frankfurt branch should have full access to the internal network:Local Subnet activatedSubnet Address 192.168

Pagina 5 - SuSE Linux – Firewall on CD2

1. General settingsConnection Name SalesRepsConnection Type Wait for the connection (Server Mode)Settings for PFS Setting, Key Life Time, and Key Repl

Pagina 6

3Firewall Administration System (FAS)Figure 3.48: Configuration of Mail Relay — Dialog 1ISP Relay Activate this check box to forward all outgoing e-mai

Pagina 7

Figure 3.49: Configuration of Mail Relay — Dialog 2With ‘Next’, complete the configuration of the mail relay.The Example, Inc., ConfigurationPage 1/2 Mai

Pagina 8

3Firewall Administration System (FAS)proxy. With the netmask, this is reduced to a single computer:Local Networks 192.168.8.10/32All other parameters

Pagina 9 - The SuSE Firewall on CD 2

sion 2 of SSH, the files id-dss.pub and id-rsa.pub are involved.Select them and the key appears in the list (see Figure 3.51).Figure 3.51: Import KeyEn

Pagina 10

3Firewall Administration System (FAS)The Example, Inc., ConfigurationPage 1/2 Administration via SSHRemote access to the firewall should be possible onl

Pagina 11 - Introduction

Figure 3.52: Specifying the NTP Time ServerAssuming you have activated the forwarding of log files for all active firewallconfigurations to the Adminhost

Pagina 12

3Firewall Administration System (FAS)the window, providing a summary of the data recorded. This view is dividedas follows:SYSLOG Configuration Name of

Pagina 13 - SuSE Firewall on CD 2

1IntroductionIntroductionThe importance of the Internet, the communication possibilities provided, andthe information-gathering options offered seem t

Pagina 14 - System Requirements

Evaluating the Log FilesLog files often become very large, depending on the type of data recordedand the duration of recording. With the search mask of

Pagina 15

3Firewall Administration System (FAS)Figure 3.53: IP Filter StatisticsBlocked Packet Report A pie chart shows the proportion of packets blockedgrouped

Pagina 16 - 8 System Requirements

Domain Report This report is similar to the ‘Organization Report’, however,sorting is done according to domain extensions, such as .com.Packet Size Re

Pagina 17

3Firewall Administration System (FAS)Figure 3.54: Interface StatisticsCertificate ManagementAccess the certificate management module in FAS with ‘Tools’

Pagina 18 - Network Planning

Figure 3.55: List of Certificateshave them signed. You can also generate your own CA and sign your certifi-cates yourself. This is sufficient for most pu

Pagina 19

3Firewall Administration System (FAS)Key size: Choose the key size here. A longer key is more difficult tohack. Choose 1024 or 2048 bits.After you have

Pagina 20 - Typical Firewall Setups

Figure 3.56: Dialog for Creating CertificatesExporting CertificatesSelect ‘Certificate Management’ ➝ ‘Export Certificate’. There are three differ-ent form

Pagina 21

3Firewall Administration System (FAS)Saving the ConfigurationSave your configuration by clicking ‘Configuration’ ➝ ‘Save’ or ‘Save All’. Ifyou try to lea

Pagina 22

online help. To leave the file editor, select ‘Finish’ from the menu. Save yourmodifications to configuration files by pressing ‘Finish’.Testing the Config

Pagina 23 - SuSE Adminhost for Firewall

3Firewall Administration System (FAS)Documenting Configuration, Tests, and Re-sultsIt is very important to document the configuration, the tests conduct

Pagina 24 - Language Selection

Most companies rely on their own networks to exchange and process mission-critical information for in-house purposes, such as an intranet, databases,a

Pagina 26 - Preparing the Hard Disk

4SuSE Live CD for FirewallSuSE Live CD for FirewallThe Live CD for the SuSE Firewall on CD is the executable part of the fire-wall. It is a minimal SuS

Pagina 27

Using proxies and not forwarding IP packets are not enough to prevent un-desired Internet IP packets from reaching the intranet or vice versa. Thisfire

Pagina 28 - Setting the root Password

4SuSE Live CD for FirewallDescriptionThe SuSE Linux Live CD for Firewall is a live file system CD from which allthe applications run directly. Theoreti

Pagina 29

pppoed DSL supportfasfw FAS net filter scriptsyslogd Daemon for system loggingiptables Packet filtercron and logrotate Rotation of local log filesTo comp

Pagina 30 - Manual Network Configuration

4SuSE Live CD for FirewalliptablesA typical iptables filter rule is very simple in theory. It normally consists offour parts:1. a basic operation with

Pagina 31

Figure 4.1: Course of a Packet with iptablesPREROUTING, OUTPUT, and POSTROUTING. Figure 4.1 attempts to illustratethe interplay of nat and filter tabl

Pagina 32

4SuSE Live CD for FirewallProtocol type: TCP, UDP, ICMPSource portDestination portICMP typeSource addressDestination addressInterface: eth0, ppp0, etc

Pagina 33

ICMP Because ICMP packets do not use any port numbers, other selectioncriteria must be used. A list of possible parameters can be obtainedwith the com

Pagina 34

4SuSE Live CD for FirewallSubsequent Treatment of Packets (Targets)After a packet has been successfully identified, a rule must know what itshould do w

Pagina 35

1Introductionfirewalls is to fend off attacks directed at your intranet as well as to regulate andprotect clients on your LAN by imposing an access pol

Pagina 36

Figure 4.2: Comparing IPSec and SSLthe network can be encrypted as well as the communication between singlecomputers or subnetworks.It is no problem t

Pagina 37

4SuSE Live CD for Firewallonly valid for a short period. If necessary, a rekey process can be started whilethe connection still exists to replace the

Pagina 38 - The User fwadmin for the FAS

SquidSquid is an HTTP proxy that offers extensive configuration options. Con-trol over the network clients’ access to the web is implemented by means o

Pagina 39 - Upgrade to the VPN Edition

4SuSE Live CD for FirewallExternal to InternalTo operate an FTP server, define the settings in this part of the module toenable access from the Interne

Pagina 40 - 32 Upgrade to the VPN Edition

with an ext2 file system and contain the label "SuSE-FWFloppy". Without thislabel, the configuration floppy is not recognized. The FAS (Firewal

Pagina 41 - System (FAS)

4SuSE Live CD for FirewallIf necessary, additional options can be passed to the module, such asthe IRQ or the IO addresses of the hardware used. Lines

Pagina 42 - Using the FAS

/etc/rc.config SuSE Linux central configuration file./etc/rc.config.d/ This directory contains files used when services arestarted, for example:/etc/rc.co

Pagina 43

4SuSE Live CD for FirewallCautionNo password may be specified for any existing users apart fromroot. Do not change this file.Caution/etc/squid.conf Confi

Pagina 44 - Creating a New Configuration

/opt the contents of the /opt directory on the configuration floppy arecopied to the running system in /opt. The user can store his files inthis director

Pagina 45

5IPsec Client on Windows XP and Windows 2000IPsec Client on Win-dows XP and Windows 2000You can configure the connection manually with the program ipse

Pagina 46 - Internet

our case, is based on the concept of an application-level gateway combined withIP packet filtering. The firewall’s routing and gateway capabilities are

Pagina 47 - The Headquarters in Nuremberg

to connect to Windows 2000. The ServicePack2 is available from http://www.microsoft.com/windows2000/downloads/servicepacks/sp2/sp2lang.asp.For Windows

Pagina 48 - The Branch in Munich

5IPsec Client on Windows XP and Windows 2000Importing a Root CertificateRight-click ‘Trusted Root Certificates’. In the drop-down menu, select ‘AllTasks

Pagina 49 - Configuring the Base Setup

Editing ipsec.confGo to the directory C:\ProgramFiles\IPsec. Open the file ipsec.confwith an editor. Adjust the data following the syntax in example 6.

Pagina 50 - 42 Using the FAS

5IPsec Client on Windows XP and Windows 2000Closing the ConnectionTo deactivate the IPsec filters and the tunnel, enter IPSEC.exe -delete.Create deskto

Pagina 52 - 44 Using the FAS

6Implementing the FirewallImplementing the FirewallOn the Adminhost, you created a configuration for the Live CD using FAS ormanually created a configur

Pagina 53

Requirements for Successful ImplementationFirst, check to see if your host boots using the configuration set up. Also seeif the selected services start

Pagina 54 - 46 Using the FAS

6Implementing the Firewalland process requests properly. Adminhost tools are available on the firewallfor these purposes (see 2 on page 15), such as nm

Pagina 55

External TestingTest externally to see if the available services are working. For instance, ifyou can send e-mails to the internal network. You should

Pagina 56 - 48 Using the FAS

7HelpHelpIn this chapter, find information about creating a setup concept for a firewallsolution in your network using the SuSE Firewall on CD. Also find

Pagina 57 - ↵ or click ‘Add’ af

1IntroductionELSA Quickstep 1000 PCIGeneric HFC 2BDSO PCISCSI Host Adapters:53c7,8xx: NCR 53c7,8xx (old driver)AM53C974: AM53/79C974BusLogic: BusLogic

Pagina 58 - 50 Using the FAS

TroubleshootingFind help here if the Adminhost cannot be installed or if the Live CD is notbooting.Problems Installing the AdminhostIf you have troubl

Pagina 59 - Page 3/5 of the Base Setup

7HelpIs external access to available resources not functioning? Which servicesare affected? Should the resources really be accessible?Test, using ps,

Pagina 60 - 52 Using the FAS

Recognizing an IntrusionFirst, understand which actions are defined as intrusions. Unfortunately, itis normal these days that a host connected to the I

Pagina 61 - IP Forward

7HelpList all running processes with ps and search for processes that do nottypically occur in normal firewall operation.Draw up a process table when s

Pagina 62 - Destination NAT

External AttacksInform the system administrator responsible for the address block (via post-master or the domain’s abuse address). The report of an in

Pagina 63 - ICMP to Firewall

7HelpExamples:Log in to the console.Examine the log files for messages of the IP filter.Search for certain unusual IP addresses (frequently occurring re

Pagina 64 - 56 Using the FAS

Recommended ReadingD. Brent Chapman & Elizabeth D. Zwicky: Building Internet Firewalls,2nd edition, O’Reilly 2000.Maximum Linux Security, SAMS 199

Pagina 65

8Suppor t, Maintenance, and Patch ManagementSupport, Maintenance,and Patch ManagementMaintenanceWith SuSE Maintenance, always have the most up-to-date

Pagina 66 - 58 Using the FAS

Patches for the Admin CDThere are two possibilities here:Via the SuSE Maintenance WebLog in to the SuSE Maintenance Web and download patches individua

Pagina 67 - Kernel Runtime Setup

8Suppor t, Maintenance, and Patch ManagementAdmin CD, download the patches via the SuSE Maintenance Web and burnthe ISO file to a CD. Find instructions

Pagina 68 - System Logging

psi240i: PSI-240iqlogicfas: Qlogic FASqlogicfc: QLogic ISP 2100 SCSI-FCPqlogicisp: QLogic ISP 1020qlogicpti: PTI Qlogic ISP Driverseagate: Seagate ST-

Pagina 69 - DNS Forwarder

speed sets the speed of the burning process-eject ejects the CD after burning is completedFind more options in the man page for cdrecord (man cdrecord

Pagina 70 - 62 Using the FAS

8Suppor t, Maintenance, and Patch ManagementMail:Address: SuSE Linux AG— Support —Deutschhernnstr. 15-19D-90429 NürnbergProcessing: weekdaysCommercial

Pagina 71 - FTP Proxy — External

D-90429 NürnbergTel: +49-911-740-53-0Fax: +49-911-740-53-479E-mail: [email protected] by our Regional Service Centers in Germany and outside, as

Pagina 72 - 64 Using the FAS

8Suppor t, Maintenance, and Patch ManagementFeedbackWe always appreciate your tips, hints, and problem descriptions. We willhelp you if your problem i

Pagina 73

[email protected] — Discussion of security issues in [email protected] — Announcement of security-related errors and upd

Pagina 74 - FTP Proxy — Internal

ADNS — Domain Name ServiceDNS — Domain Name ServiceDNS (Domain Name Service) is needed to resolve domain and host namesinto IP addresses. This chapter

Pagina 75

Starting the Name Server BINDThe name server BIND is already preconfigured in SuSE Linux, so you caneasily start it right after installing the distribu

Pagina 76 - 68 Using the FAS

ADNS — Domain Name Serviceoptions {directory "/var/lib/named";forwarders { 10.11.12.13; 10.11.12.14; };listen-on { 127.0.0.1; 192.168.0.99;

Pagina 77 - Generic TCP Proxy

};zone "0.0.127.in-addr.arpa" in {type master;file "127.0.0.zone";};zone "." in {type hint;file "root.hint";};

Pagina 78 - 70 Using the FAS

ADNS — Domain Name Serviceallow-query 127.0.0.1; 192.168.1/24; ; defines the networks from whichclients can post DNS requests. The /24 at the end is an

Pagina 79

1Introductiondepca: DEPCA,DE10x,DE200,DE201,DE202,DE422dgrs: Digi Intl. RightSwitch SE-Xdmfe: DM9102 PCI Fast Ethernete100.o: EtherExpress PRO/100 (In

Pagina 80 - 72 Using the FAS

Zone Entry Structurezone "my-domain.de" in{type master;file "my-domain.zone";notify no;};File 11: Zone Entry for my-domain.deAfter

Pagina 81

ADNS — Domain Name Servicemasters { 10.0.0.1; }; This entry is only needed for slave zones. It specifiesfrom which name server the zone file should be t

Pagina 82 - 74 Using the FAS

Line 1: $TTL defines the standard TTL that applies for all the entries in thisfile, here 2 days. TTL means “time to live”.Line 2: The SOA control record

Pagina 83 - Defining ACLs

ADNS — Domain Name ServiceLine 9: The IN NS specifies the name server responsible for this do-main. The same is true here that gateway is extended to g

Pagina 84 - 76 Using the FAS

Line 1: $TTL defines the standard TTL that applies to all entries here.Line 2: ’Reverse lookup’ should be activated with this file for the network192.16

Pagina 85 - Arranging ACLs

BProxy Server: SquidProxy Server: SquidThe following chapter describes how caching web sites assisted by a proxyserver works and what the advantages o

Pagina 86 - 78 Using the FAS

What is a Proxy Cache?Squid acts as a proxy cache. It behaves like an agent that receives requestsfrom clients, in this case web browsers, and passes

Pagina 87

BProxy Server: SquidMultiple Caches“Multiple caches” means configuring different caches so that objects can beexchanged between them, reducing the tota

Pagina 88 - and ‘String’ are optional

The question remains as to how long all the other objects stored in the cacheshould stay there. To determine this, all objects in the cache are assign

Pagina 89 - Access Configuration

BProxy Server: Squidrequests per second = 1000 / seek timeSquid enables more disks to be used simultaneously, increasing the numberof requests per sec

Pagina 90 - 82 Using the FAS

smc9194: SMC 9194tlan: Compaq Netelligent 10/100/NetFlex 3tulip: DEC Tulip (DC21x4x) PCIvia-rhine: VIA VT86c100A Rhine-IIwd: Western Digital WD80x3yel

Pagina 91

time of a hard disk, about 10 milliseconds, with the 10 nanoseconds accesstime of the newer RAM memories)Every object in RAM memory has a size of 72 b

Pagina 92 - IPsec VPN Tunnel

BProxy Server: Squidproxy in the browser. To allow all users to access Squid and thus the In-ternet, change the entry in the configuration file /etc/squ

Pagina 93 - General Settings

If you have updated an earlier Squid version, it is recommended to edit thenew /etc/squid.conf and only apply the changes made in the previousfile. If

Pagina 94 - 86 Using the FAS

BProxy Server: Squidcache_store_log /var/squid/logs/store.log path for log messageThese three entries specify the path where Squid will log all of its

Pagina 95 - IP Filter

Squid will make a note of the failed requests then refuse to issue newones, although the Internet connection has been reestablished. In a casesuch as

Pagina 96 - 88 Using the FAS

BProxy Server: Squidshould always be http_access deny all. In the following example,the localhost has free access to everything while all other hosts

Pagina 97

ident_lookup_access allow hacl_namei With this, you will manage to havean ident request run through for all ACL-defined clients to find outeach user’s i

Pagina 98 - ➝ ‘Create Certificate’:

BProxy Server: SquidKernel ConfigurationFirst, make sure that the proxy server’s kernel has support for transparentproxies. Otherwise, add this option

Pagina 99

SquidGuard is a free (GPL), flexible, and ultra fast filter, redirector, and “ac-cess controller plugin” for Squid. It lets you define multiple access ru

Pagina 100 - 92 Using the FAS

BProxy Server: SquidNow, tell Squid to use SquidGuard. Use the following entries in the /etc/squid.conf file:redirect_program /usr/bin/squidGuardThere

Pagina 101

1IntroductionSecurity PolicyThe security policy provides the basis for working with all programs, hosts,and data. In addition, it outlines how to guar

Pagina 102 - Configuring the Mail Relay

Another powerful cache report generator tool is SARG (Squid Analysis Re-port Generator), included in series n. Further information on this can befound

Pagina 103

CNetwork SecurityNetwor k SecurityThis chapter provides detailed information about several aspects of networksecurity. It begins with information abou

Pagina 104 - 96 Using the FAS

Masquerading and FirewallsOwing to its outstanding network capabilities, Linux is becoming morewidespread as a router operating system for dial-up or

Pagina 105 - Administration via SSH

CNetwork SecurityNoteMake sure that both the broadcast addresses and the network masksare the same for all the hosts when configuring your network.Note

Pagina 106 - 98 Using the FAS

For such a connection, there would be no entry in the table because, the en-try itself is only created if an internal host opens a connection with the

Pagina 107 - Log File Analysis

CNetwork Securityallowed through. This gateway or proxy pretends to be the actual client ofthe server. In a sense, such a proxy could be considered a

Pagina 108 - 100 Log File Analysis

For a firewall without masquerading, only set this to yes if you wantto allow access to the internal network. Your internal hosts need to useofficially

Pagina 109 - The Log Files

CNetwork SecurityFor example: "172.20.0.0/16 172.30.4.2" means that all hostswhich have an IP address beginning with 172.20.x.x, along with

Pagina 110 - The IP Filter Statistics

SSH — Secure Shell, the Safe AlternativeIn these times of increasing networks, accessing a remote system also be-comes more common. Regardless of the

Pagina 111

CNetwork SecurityFollowing successful authentication, work from the command linethere or use interactive applications. If the local user name is diffe

Pagina 112 - Mail Statistics

1st edition 2002Copyright ©This publication is intellectual property of SuSE Linux AG.Its contents can be duplicated, either in part or in whole, prov

Pagina 113 - Certificate Management

Protocol icmp ftp ssh smtp http https . . .Client internal external i. e. i. e. i. e. i. e. i. e.host1 x – x – – – x – x – –host2 x – – – x – x – – –

Pagina 114 - 106 Certificate Management

The SSH Daemon (sshd) — Server-SideTo work with the SSH client programs ssh and scp, a server, the SSH dae-mon, has to be running in the background. T

Pagina 115 - Importing Certificates

CNetwork SecurityIt is recommended to securely archive the private and public keys stored in/etc/ssh/ externally. In this way, key modifications can be

Pagina 116 - Exporting Certificates

ssh-agent, which retains the private keys for the duration of an X session.The entire X session will be started as a child process of ssh-agents. Thee

Pagina 117 - Editing Configuration Files

CNetwork Securityusers in an existing SSH connection. The SMTP and POP3 host must be setto localhost for this.Additional information can be found in t

Pagina 118 - Testing the Configuration

using a network linkIn all these cases, a user should be authenticated before accessing the re-sources or data in question. A web server might be less

Pagina 119 - Monitoring the Firewall

CNetwork Securityserial terminals are a special case. Unlike network interfaces, they do notrely on a network protocol to communicate with the host. A

Pagina 120

This is a general rule to be observed, but it is especially true for the userroot who holds the supreme power on the system. User root can take onthe

Pagina 121 - SuSE Live CD for Firewall

CNetwork Securitybuddy” or “jasmine76” are easily guessed even by someone who has onlysome casual knowledge about you.The Boot ProcedureConfigure your

Pagina 122 - Hardware Requirements

directory. The purpose of these files is to define special permissions, suchas world-writable directories or, for files, the setuser ID bits, which means

Pagina 123 - Services on the Firewall

CNetwork Securityhave serious consequences, in particular if the program is being executedwith special privileges (see Section C on page 199).“Format

Pagina 124 - 116 Services on the Firewall

1IntroductionFigure 1.2: Simple SetupFigure 1.3: Effective and Manageable Setupstops any illegal requests at the packet level. Packets allowed through

Pagina 125

Network SecurityLocal security is concerned with keeping different users on one system apartfrom each other, especially from root. Network security, o

Pagina 126 - 118 Services on the Firewall

CNetwork SecurityID card of some kind. This cookie (the word goes back not to ordinary cook-ies, but to Chinese fortune cookies which contain an epigr

Pagina 127

posted on the security mailing lists. They can be used to target the vulnera-bility without knowing the details of the code. Over the years, experienc

Pagina 128 - 120 Services on the Firewall

CNetwork SecurityFinally, we want to mention “spoofing”, an attack where packets are modifiedto contain counterfeit source data, mostly the IP address.

Pagina 129

very good way to protect your systems against problems of all kinds is to getand install the updated packages recommended by security announcementsas

Pagina 130 - 122 Services on the Firewall

CNetwork Securityintended to be available in the first place (the legacy problem). Openports, with the socket state LISTEN, can be found with the progr

Pagina 131

the end, only you can know which entries are unusual and which arenot.Use tcp_wrapper to restrict access to the individual services run-ning on your m

Pagina 132 - FTP Proxy

DYaST and SuSE Linux License TermsYaST and SuSE LinuxLicense TermsYaST 2 Copyright (c) 1995 - 2001 SuSE GmbH, Nuernberg (Germany)YaST 2 Copyright (c)

Pagina 133 - The Configuration Disk

programmes are observed. The use of YaST2, even if a modified versionis used, does not exempt in particular the Licensee from the duty totake due care

Pagina 134 - The Configuration Files

DYaST and SuSE Linux License Termssources and this licence in accordance with 2b. Making YaST2 or worksderived thereof available free of charge togeth

Pagina 137

EThe GNU General Public LicenseThe GNU Gen-eral Public LicenseGNU General Public LicenseCopyright (C) 1989, 1991 Free Software Foundation, Inc.59 Temp

Pagina 138 - Boot Parameters

the software or use pieces of it in new free programs; and that you know youcan do these things.To protect your rights, we need to make restrictions t

Pagina 139 - IPsec Client on Win

EThe GNU General Public Licenseconstitute a work based on the Program (independent of having been madeby running the Program). Whether that is true de

Pagina 140

whole which is a work based on the Program, the distribution of the wholemust be on the terms of this License, whose permissions for other licenseesex

Pagina 141 - Installing the ipsec.exe Tool

EThe GNU General Public Licensebinary form) with the major components (compiler, kernel, and so on) of theoperating system on which the executable run

Pagina 142 - Editing ipsec.conf

only way you could satisfy both it and this License would be to refrain en-tirely from distribution of the Program.If any portion of this section is h

Pagina 143 - Closing the Connection

EThe GNU General Public LicenseOur decision will be guided by the two goals of preserving the free status ofall derivatives of our free software and o

Pagina 144

published by the Free Software Foundation; either version 2 ofthe License, or (at your option) any later version.This program is distributed in the ho

Pagina 145 - Implementing the Firewall

IndexAACLs- arranging . . . . . . . . . . . . . . . . . . . . . . . . . 77- defining . . . . . . . . . . . . . . . . . . . . . . . . . . 75Adminhost .

Pagina 146 - Testing the Firewall

2SuSE Adminhost for FirewallSuSE Adminhost for FirewallIt is no easy task to administer, maintain, and monitor a firewall. Above all, theimportance of

Pagina 147

- ntp.conf . . . . . . . . . . . . . . . . . . . . . . . . . 127- pam.d . . . . . . . . . . . . . . . . . . . . . . . . . . . 127- permissions . . . .

Pagina 148 - Going Online

- proxy filters . . . . . . . . . . . . . . . . . . . . . . 78httpf . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 124Iifconfig

Pagina 149

Rroot- password . . . . . . . . . . . . . . . . . . . . . . . . . 20routing- masquerading . . . . . . . . . . . . . . . . . . . 184RPM- security . . .

Pagina 150 - Troubleshooting

upgrading- VPN . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 31users- fwadmin . . . . . . . . . . . . . . . . . . . . . . . . . . 34VVPN

Pagina 151 - Detecting Attacks

After installing the SuSE Adminhost for Firewall, theFirewall Administration System (FAS) is available. The FAS is a tool with agraphical administrati

Pagina 152 - 144 Detecting Attacks

2SuSE Adminhost for FirewallTab moves the focus forward an entry or selection field or a button.Shift +Tab moves the focus to the previous

Pagina 153

Figure 2.1: YaST2: Keyboard Layout and Time ZoneNow test your keyboard. By clicking with the mouse or usingTab , activatethe entry line and type i

Pagina 154 - External Attacks

2SuSE Adminhost for FirewallFigure 2.2: YaST2: Preparing the Hard DiskStep 2One of the following situations could occur:If the hard disk is not empty,

Pagina 155 - Examples:

Once the installation starts and all requirements have been fulfilled, YaST2partitions and formats the necessary hard disk space on its own. The entire

Pagina 156 - Recommended Reading

2SuSE Adminhost for FirewallNoteRemember the root password very carefully, as you cannot retrieve itlater. This password whenever you perform administ

Pagina 157 - Support, Maintenance

ContentsPreface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11 Introduction 3SuSE Firewall on CD 2 . . . . . . . . . . . .

Pagina 158 - 150 Maintenance

resolution, color resolution, and repetition rate frequency are selected for themonitor and a test screen is displayed.NoteCheck the settings before a

Pagina 159

2SuSE Adminhost for FirewallFigure 2.4: YaST2: Network ConfigurationConfiguration FilesThis section provides an overview of the network configuration file

Pagina 160 - Support and Services

Figure 2.5: YaST2: Configuring the Name Serverconsisting of the IP address, the fully qualified host name, and the hostname (e. g., earth) is entered in

Pagina 161 - Commercial Support

2SuSE Adminhost for Firewall## networks This file describes a number of net name-to-address# mappings for the TCP/IP subsystem. It is mostly# used at

Pagina 162 - SuSE Training Program

An example for /etc/host.conf is shown in File 3.## /etc/host.conf## We have named runningorder hosts bind# Allow multiple addrsmulti on# End of host.

Pagina 163 - Additional Services

2SuSE Adminhost for FirewallThe “databases” available over NSS are listed in Table 2.2. In addition,automount, bootparams, netmasks, and publickey are

Pagina 164 - 156 Support and Services

files directly access files, for example, to /etc/aliases.db access via a database.nis NISnisplusdns Only usable by hosts and networks as an exten-sion

Pagina 165 - DNS — Domain Name Service

2SuSE Adminhost for Firewall# /etc/resolv.conf## Our domainsearch cosmos.com## We use sun (192.168.0.1) as name servername server 192.168.0.1# End of

Pagina 166 - Starting the Name Server BIND

/etc/init.d/nfsserverStarts the NFS server./etc/init.d/sendmail Controls the sendmail process dependingon the configuration in /etc/rc.config./etc/init

Pagina 167

2SuSE Adminhost for FirewallAssign a password for the firewall admin user here. This password must beat least five characters in length. In the next scr

Pagina 168

3 Firewall Administration System (FAS) 33Logging in as fwadmin . . . . . . . . . . . . . . . . . . . . . . . . . . . 34Starting the Firewall Administr

Pagina 169

Then start the YaST2 Control Center and select ‘Install Patch CD’. Follow theinstructions there.When the installation is finished, restart the FAS daem

Pagina 170 - Zone Entry Structure

3Firewall Administration System (FAS)Firewall AdministrationSystem (FAS)FAS is the graphical administration interface used to create the configurationfl

Pagina 171

Logging in as fwadminAfter installation, the system boots to the graphical login. Log in here as theuser fwadmin and use the corresponding password. T

Pagina 172

3Firewall Administration System (FAS)Figure 3.2: Creating a New Configurationon CD and, for this reason, is checked for its suitability with the progra

Pagina 173

Figure 3.3: Creating a New AccountCreating a New ConfigurationA configuration is created on the inital login. To create additional new con-figurations, s

Pagina 174 - For More Infor mation

3Firewall Administration System (FAS)Figure 3.4: Starting a New ConfigurationKernel Runtime Setup (kernel configuration)System Logging (settings for log

Pagina 175 - Proxy Server: Squid

SSH Admin Login (login for the administrator with SSH)Time Synchronization (configuration of xntpd to synchronize computertime with a time server)Examp

Pagina 176 - What is a Proxy Cache?

3Firewall Administration System (FAS)The SetupExample, Inc., an online bookshop with its headquarters in Nuremberg, has150 staff. It operates branches

Pagina 177

80.80.80.1. The DNS service is available from the provider under the IPaddresses 123.123.123.123 and 123.123.123.124. The following entrieshave alread

Pagina 178

3Firewall Administration System (FAS)Network PoliciesHeads of department in each branch should have full access to the Internet,but all other staff ma

Pagina 179

Log File Analysis . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 99The Log Files . . . . . . . . . . . . . . . . . . . . . . . . . . .

Pagina 180 - Starting Squid

BasicsIn ‘Basics’, either disable the root password completely (default) or set it.As a safety precaution, repeat the root password (see Figure 3.7).

Pagina 181

3Firewall Administration System (FAS)Figure 3.8: Configuring the Hard DiskDisk Swap Space: Size of the swap partition, such as 128 MFurther Options Act

Pagina 182

Figure 3.9: Network Interfaces1. Make these settings in the ethernet dialog (Figure 3.11 on the facingpage):Interface Names are automatically allocate

Pagina 183

3Firewall Administration System (FAS)Figure 3.10: Selecting Network InterfacesFigure 3.11: Ethernet Interface2. The configuration dialog for DSL is div

Pagina 184 - Options for Access Controls

conf for DSL. This file is involved with the resolution of hostnames by the resolver library and contains the domain of the hostand the IP address of t

Pagina 185

3Firewall Administration System (FAS)Figure 3.12: ISDN Configuration — Part 1Interface’s Phone Number (MSN) Enter the phone number of theISDN device (M

Pagina 186

Figure 3.13: ISDN Configuration — Part 2RoutingIn a dialog like Figure 3.14 on the next page), view, create, and modifyroutes. ‘Add’ creates a new rout

Pagina 187 - Squid and Other Programs

3Firewall Administration System (FAS)Figure 3.14: Routing DialogNetmask The relevant netmask.Interface Select the interface to use.Save your settings

Pagina 188

Figure 3.15: RoutingIn the next entry line, the search lists are specified, for example,your-company-inc.com.If you now click ‘Finish’, the base configu

Pagina 189

3Firewall Administration System (FAS)Figure 3.16: Host and Domain ConfigurationOnly entire hard disks can be used. Individual partitions cannot be confi

Pagina 190 - More Information on Squid

5 IPsec Client on Windows XP and Windows 2000 131Exporting the Required Certificates . . . . . . . . . . . . . . . . . . . . . 131Importing the Certific

Pagina 191 - Networ k Security

Now the network card (eth1) leading to the DMZ is configured. It shouldbe responsible for a subnet of the public IP addresses. How this subnet ismade a

Pagina 192 - Masquerading and Firewalls

3Firewall Administration System (FAS)Firewall host name: fw-nbgFirewall domain: example.comAs the name server, the firewall should use the internal DNS

Pagina 193 - Network Security

Figure 3.17: IP Forward DialogMasqueradingThe same entry fields are available in ‘Masquerading’ (see Figure 3.18 on thenext page). Masquerading is a sp

Pagina 194 - Firewalling Basics

3Firewall Administration System (FAS)Figure 3.18: Masquerading DialogDestination Port For ‘From:’, enter the destination port. For ‘To:’, define aserie

Pagina 195

Figure 3.19: Dialog for Destination NATSource Address Enter the source IP address.Destination Address Select the destination address.ICMP Select the m

Pagina 196

3Firewall Administration System (FAS)Figure 3.20: Dialog for ICMPAddress the internal DNS server from the DMZProtocol UDPLocal address 192.168.8.8/255

Pagina 197

POP3 access to the mail server for clients from the internal net-workProtocol TCPLocal address 192.168.10.0/255.255.255.0Remote address 192.168.8.10fr

Pagina 198 - The ssh Program

3Firewall Administration System (FAS)Protocol TCPLocal address 192.168.10.0/255.255.255.192Remote address 0.0.0.0from Port 1to Port 65535Protocol UDPL

Pagina 199

Figure 3.21: Kernel Runtime SettingsSystem LoggingIn this dialog, shown in Figure 3.22 on the next page, configure the behav-ior of the Syslog daemon.

Pagina 200

3Firewall Administration System (FAS)Figure 3.22: Settings for Syslog Daemonnation for the log files: 192.168.10.254. ‘Enable Log and Traffic Evalua-tio

Pagina 201

8 Support, Maintenance, and Patch Management 149Maintenance . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 149Accessing the SuSE Ma

Pagina 202

Figure 3.23: DNS Configurationrules generated automatically and specify the IP addresses of the hosts towrite to the file hosts.allow.The Example, Inc.,

Pagina 203 - Security and Confidentiality

3Firewall Administration System (FAS)Figure 3.24: DNS Access ConfigurationPage 2/2 of the DNS Configuration‘Configure IP filter rules automatically’ must

Pagina 204

Figure 3.25: Configuration of the FTP ServerFTP proxy port Port on which the FTP proxy is addressed, normally port21. Viewed from the outside, this tur

Pagina 205

3Firewall Administration System (FAS)IP address of the FTP server Enter the IP address of the FTP server locatedin the intranet or in the DMZ.FTP serv

Pagina 206 - Passwords

You will not expect many clients to want access to the FTP service at thesame time. To avoid an overloaded line, the maximum number of clientswho can

Pagina 207

3Firewall Administration System (FAS)Figure 3.27: Configuration of the Internal FTP ProxyPort reset PASV By default, this check box is activated, so pa

Pagina 208 - File Race Conditions

In the second mask, shown in Figure 3.28), configure access to the internalFTP proxy. By default, automatic generation of filter rules is activated. Sel

Pagina 209

3Firewall Administration System (FAS)Page 2/2 Internal FTP Proxy ConfigurationIn this module, the filter rules are also generated automatically. The int

Pagina 210

Figure 3.29: Configuration of the Generic Proxyand asterisk (‘*’). The wild card ‘?’ stands for any character at all. Aster-isk ‘*’ represents any numb

Pagina 211

3Firewall Administration System (FAS)Figure 3.30: Redirect Settings for rinetdThe Example, Inc., ConfigurationGeneric TCP ProxyIn Example, Inc., new sa

Pagina 212 - DoS — Denial of Service

Kernel Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . 179Configuration Options in /etc/squid.conf . . . . . . . . . . . . . . 179Squi

Pagina 213

allow activatedPattern 80.80.60.*3. IP Filter ConfigurationNo further restrictions need to be made in the “IP Filter Configuration”tab. Only the standar

Pagina 214

3Firewall Administration System (FAS)Figure 3.31: Configuration of the External HTTP ProxyThe Example, Inc., ConfigurationPage 1/2 HTTP Proxy — External

Pagina 215

Figure 3.32: Access to the External HTTP Proxyto 0.0.0.0/0.0.0.0.Configuring the HTTP Proxy for Internal ConnectionsIn the ‘HTTP Proxy — Internal’ modu

Pagina 216

3Firewall Administration System (FAS)Figure 3.33: Configuration of the Internal HTTP ProxyTransparent Proxy Because HTTP requests from clients normally

Pagina 217 - YaST and SuSE Linux

Figure 3.34: Define ACLsurl_regex Details of URL address using regular expressions.proto (protocol) Specify the appropriate protocol here.src (source)

Pagina 218

3Firewall Administration System (FAS)Add Add the new ACL to the list of already created ACLs.Edit If you click ‘Edit’, a window opens in which to ente

Pagina 219

Define, via ‘Negate ACL’, an ACL to use in negated form.A new rule is integrated with ‘Add’. It is then be listed in the list fieldof defined ACLs.With t

Pagina 220

3Firewall Administration System (FAS)Figure 3.36: Content Filter Dialogallow allows the selected tag/attribute.log creates an entry in the log file, wh

Pagina 221 - The GNU Gen

makes sense to enter something else here if you have chosen ‘replcont’,‘replabort’, ‘replskip’, or ‘replendskip’ as the action. Click ‘Add’ to gen-era

Pagina 222 - GNU General, Public License

3Firewall Administration System (FAS)Figure 3.37: Mime Type FilterEnter the appropriate HTTP port of the provider is entered in ‘Parent ProxyPort’. Re

Pagina 223

PrefaceMany thanks to Jürgen Scheiderer, Carsten Höger, Remo Behn, Thomas Biege,Roman Drahtmüller, Marc Heuse, and Stephan Martin.The SuSE Firewall on

Pagina 224

Figure 3.38: Configuration of the Internal HTTP ProxyProxy Mode activatedCache activatedMB Cache 1000TipTransparent Proxy and CachingBecause a transpar

Pagina 225

3Firewall Administration System (FAS)Figure 3.39: Access to the Internal HTTP ProxyThe values for the ACL are entered by selecting them then editing t

Pagina 226

Page 7/7 HTTP Proxy — InternalThe proxy should only be used by clients from the internal network. For thisreason, access is restricted to this network

Pagina 227 - No Warranty

3Firewall Administration System (FAS)Figure 3.40: Select the Local CertificateGeneral SettingsThis dialog is shown in Figure 3.42 on page 87. Assign a

Pagina 228

Figure 3.41: Available CertificatesVPN ConnectionThe ‘VPN connection’ tab is shown in Figure 3.43 on page 88. Under ‘Lo-cal Configuration’, activate the

Pagina 229

3Firewall Administration System (FAS)Figure 3.42: VPN: General SettingsA shared key is a random string. Quotation marks (") may not occur in thes

Pagina 230 - 222 Index

Figure 3.43: VPN ConnectionTo define a rule, first select the transmission protocol: tcp, udp, or icmp. Ifyou select tcp or udp, you only need to specif

Pagina 231

3Firewall Administration System (FAS)Figure 3.44: Authentication for a VPN ConnectionWhen satisfied with all the dialogs, click ‘Ok’.Information about

Pagina 232 - 224 Index

Figure 3.45: Filter Rules for a VPN ConnectionCommon Name RootCAE-mail Address [email protected] unit edvOrganization Example, Inc.Local

Pagina 233

3Firewall Administration System (FAS)Figure 3.46: Masquerading for a VPN ConnectionCommon Name Firewall-nbgE-mail Address [email protected]

Comentarios a estos manuales

Sin comentarios