Koozali.org: home of the SME Server

OPen ports - eep!

Rob K

OPen ports - eep!
« on: March 16, 2001, 07:15:50 AM »
I just did an nmap of my test server, and found a lot of open ports - for my application, this isn't practical.

All I want to see from the external interface is ssh - I'd like ipchains to drop anything else, pmfirewall style. Is there an obvious bit of documentation I haven't read?

Gordon Rowell

Ports are open for configured services (was OPen ports - eep
« Reply #1 on: March 16, 2001, 08:11:06 AM »
Rob K wrote:
>
> I just did an nmap of my test server,

Are you running this in server-only mode? If so, all packet filtering is disabled, as
server-only mode is designed for use on an internal network, behind a firewall.

If you are using server-gateway mode, please read on :-)

> and found a lot of open ports - for my application, this isn't practical.
 
We enable external access to all configured services. The e-smith server
and gateway is designed to provide gateway features plus external HTTP
and SMTP.

So, if you have http, smtp, ssh enabled, then the ports for those will be
available on the external interface.

> All I want to see from the external interface is ssh - I'd
> like ipchains to drop anything else,

You will need to disable all of the other services from the public interface.

> pmfirewall style.

Actually, this is normal firewall practice. We used some of the pmfirewall rules
as initial thoughts, but changed them to be service based so that ports are
open an closed as services are enabled/disabled via the user interface.

> Is there an obvious bit of documentation I haven't read?

You can turn off many of the services, or make them accessible only on the local
network, via the web manager.

You cannot currently disable HTTP or SMTP via the web manager. You will
need to disable these in the configuration database (/home/e-smith/configuration).

We strongly suggest leaving the qmail.init service running, even if you disable
smtpfwdd. This will allow mail to be sent by administrative processes, but will
disable the smtp listener.

Gordon

Rob K

Re: Ports are open for configured services (was OPen ports -
« Reply #2 on: March 18, 2001, 03:31:46 AM »
Hmmm - OK, I understand that much.

However, it still seems a little inflexible - for example, I'm testing e-smith on a residential cable service, as the main pipe it'll live on won't be ready for a few weeks. The AUP of this services states that I shouldn't be running any services visible on my external interface. I can normally do my intranet development this way with pmfirewall, as I can run all the services I need to fiddle with without fear of Bad Things occuring. Turning off apache just for this reason is a little limiting :)

Maybe a server/masq only install option is needed?