Re: ipf, Sunscreen or ?
Scott Wilson <[email protected]>
| Newsgroups | gmane.comp.security.sun |
|---|---|
| Message-ID | <[email protected]> |
We've used IPF and Sunscreen for a while now, and I couldn't imagine running a machine without something similar. We used IPF on all of our Solaris 7 and 8 boxes, and we use Sunscreen on all of our Solaris 9 boxes. I use the command line mode (ssadm), so running a web server to get a GUI isn't an issue. The only things that are mildly annoying is that you can't use numbers for IPs or ports in the rules. You have to first define the nubmers, then use the aliases in the rules. I guess its good in some ways, since with decent names you never run into the "So why did I open that port to that machine?" issue, but it does take a little longer. The only other annoyannce is that changing the rules using "ssadm edit" doesn't actually do anything until you either reboot, or run "ssadm activate". All in all though, Sunscreen works great. Scott Wilson Manager / Lead System Administrator [email protected] NSIT - TaRT - Systems & Servers On Wed, 22 Oct 2003, Brad Arlt wrote: > On Tue, Oct 21, 2003 at 04:49:51PM -0700, Chris Pelton wrote: > > boxes but was burned awhile back by ipf (could have been a > > There were 2 or 3 versions that had problems booting. That is fixed. > I have noticed a large CPU usage when sending lots of data, but > otherwise love IPF. > > I will be trying SunScreen this morning (to get around high CPU use > while sending), but don't have an opinion as yet. > ----------------------------------------------------------------------- > __o Bradley Arlt Security Team Lead > _ \<_ [email protected] University Of Calgary > (_)/(_) Joyously Canadian Computer Science >