Re: ipf, Sunscreen or ?

Scott Wilson <[email protected]>
Newsgroups gmane.comp.security.sun
Message-ID <[email protected]>
We've used IPF and Sunscreen for a while now, and I couldn't imagine
running a machine without something similar.

We used IPF on all of our Solaris 7 and 8 boxes, and we use Sunscreen on
all of our Solaris 9 boxes.

I use the command line mode (ssadm), so running a web server to get a GUI
isn't an issue.

The only things that are mildly annoying is that you can't use numbers for
IPs or ports in the rules.  You have to first define the nubmers, then use
the aliases in the rules.  I guess its good in some ways, since with
decent names you never run into the "So why did I open that port to that
machine?" issue, but it does take a little longer.  The only other
annoyannce is that changing the rules using "ssadm edit" doesn't actually
do anything until you either reboot, or run "ssadm activate".

All in all though, Sunscreen works great.



Scott Wilson                    Manager / Lead System Administrator
[email protected]            NSIT - TaRT - Systems & Servers

On Wed, 22 Oct 2003, Brad Arlt wrote:

> On Tue, Oct 21, 2003 at 04:49:51PM -0700, Chris Pelton wrote:
> > boxes but was burned awhile back by ipf (could have been a 
> 
> There were 2 or 3 versions that had problems booting.  That is fixed.
> I have noticed a large CPU usage when sending lots of data, but
> otherwise love IPF.
> 
> I will be trying SunScreen this morning (to get around high CPU use
> while sending), but don't have an opinion as yet.
> -----------------------------------------------------------------------
>    __o		Bradley Arlt			Security Team Lead
>  _ \<_		[email protected]		University Of Calgary
> (_)/(_) 	Joyously Canadian	 	Computer Science
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.