nanog mailing list archives
Re: it's here
From: Jesper Skriver <jesper () skriver dk>
Date: Wed, 13 Feb 2002 18:37:53 +0100
On Wed, Feb 13, 2002 at 03:55:25PM +0000, Eric Brandwine wrote:
Without control plane seperation (and it's not possible with Cisco, Juniper, or most other routers out there), management services are listening on the public network, and that makes this very scary, regardless of filtering policies, etc.
interfaces { lo0 { unit 0 { family inet { filter { input RE; } } } } } firewall { filter RE { term BGP { from { protocol tcp; destination-port bgp; } then accept; } term TCP-established { from { protocol tcp; tcp-established; } then accept; } /* insert other term's allowing routing protocol traffic etc. */ term only-fxp0 { from { interface-group-except fxp0; } then discard; } /* allow ssh, snmp etc. traffin only on the mngt. lan */ term allow-from-fxp0 { from { interface-group fxp0; } then accept; } } } /Jesper -- Jesper Skriver, jesper(at)skriver(dot)dk - CCIE #5456 Work: Network manager @ AS3292 (Tele Danmark DataNetworks) Private: FreeBSD committer @ AS2109 (A much smaller network ;-) One Unix to rule them all, One Resolver to find them, One IP to bring them all and in the zone to bind them.
Current thread:
- Re: it's here, (continued)
- Re: it's here Valdis . Kletnieks (Feb 12)
- Re: it's here Eric Brandwine (Feb 12)
- Re: it's here Sean Donelan (Feb 12)
- Re: it's here Jon O . (Feb 12)
- Re: it's here Ron da Silva (Feb 13)
- Re: it's here Eric Brandwine (Feb 13)
- Re: it's here jerry scharf (Feb 13)
- Re: it's here jlewis (Feb 13)
- Re: it's here William Allen Simpson (Feb 13)
- Re: it's here Jared Mauch (Feb 13)
- Re: it's here Jesper Skriver (Feb 13)
- Re: it's here Eric Brandwine (Feb 13)
- Re: it's here kevin graham (Feb 13)
- Re: it's here Jesper Skriver (Feb 13)
- Re: it's here Jake Khuon (Feb 13)
- Re: it's here Steve Noble (Feb 13)
- RE: it's here Tony Hain (Feb 13)
- Re: it's here Eric Brandwine (Feb 13)
- Re: it's here Christopher L. Morrow (Feb 13)
- Re: it's here Ron da Silva (Feb 13)
- Re: it's here Stephen Sprunk (Feb 14)