Security Basics mailing list archives

Re: Unix jumpbox \ console


From: Leif Ericksen <leife () dls net>
Date: Wed, 28 Jan 2004 22:27:57 -0600

JUMP BOX;  AKA HOP BOX.

How secure do you want it to be?

1) Require (Open)SSH into the box and to the servers that you are going to go to from this box. This box has 2 nics.
        1 Private network (to the desk top for instance)
        2  to the open network (the servers that you do not want direct
            access to. (they may have 2 nics 1 to the internet 1 to the
             hop box)

2) If you can afford SecureID or other one time password system require that as well.
3) Shut off ALL services but the 'essential' on the hop box.
4) DO NOT HAVE SUPER SENSITIVE DATA that is TOP SECRET Material that would be found SIPERNET or other networks of a classified nature. Attached directly in this manner unless you really know what you are doing. With this question I can tell that you are trying to dig for information so more research might be required.

Have Fun Enjoy, and do not be afraid to ask more questions.

Byron Sonne wrote:

Hi I am looking for advice on creating a secure unix jumpbox


What is a 'jumpbox'? I've never heard the term before.




---------------------------------------------------------------------------
Ethical Hacking at InfoSec Institute. Mention this ad and get $720 off any course! All of our class sizes are guaranteed to be 10 students or less. We provide Ethical Hacking, Advanced Ethical Hacking, Intrusion Prevention, and many other technical hands on courses. Visit us at http://www.infosecinstitute.com/securityfocus to get $720 off any course! ----------------------------------------------------------------------------


Current thread: