nanog mailing list archives
Re: Encrypted RPC and firewalling
From: Valdis.Kletnieks () vt edu
Date: Thu, 10 Nov 2011 07:50:39 -0500
On Thu, 10 Nov 2011 09:56:51 +0100, Lasse Birnbaum Jensen said:
I would like to know how you guys handle encypted rpc across firewalls.
You can always just set the firewall to ban RPC in general, whether or not it's encrypted (while you're there, close off ports 137-139 and other chucklehead stuff like that), and just make the user who's outside the firewall VPN in. That's a nice, simple, well-understood configuration that almost all software and even most users can handle. (We don't actually do a big monolithic firewall box - but pretty much everything has an iptables ruleset loaded that says "if your source IP isn't inside our 2 /16s, your packets go bye bye". And there's a nice PPTP-based VPN solution in place that even a humanities professor emeritus can use ;)
Attachment:
_bin
Description:
Current thread:
- Encrypted RPC and firewalling Lasse Birnbaum Jensen (Nov 10)
- Re: Encrypted RPC and firewalling Valdis . Kletnieks (Nov 10)
- RE: Encrypted RPC and firewalling Matthew Huff (Nov 10)
- Re: Encrypted RPC and firewalling Valdis . Kletnieks (Nov 10)