Discussion:
Restricting outbound TCP/IP access by account?
(too old to reply)
Alan Winston - SSRL Central Computing
2007-03-09 03:44:21 UTC
Permalink
Multinetters:

$multinet show /version
Process Software MultiNet V5.1 Rev A-X, COMPAQ AlphaServer DS20E 666 MHz,
OpenVMS AXP V8.3

I have an account that should be allowed inbound/outbound DECnet access, but
should only be allowed inbound TCP/IP access. (That is, you should be able
to SSH into it, but not, say, launch Xwindows keystroke sniffers from it.)

Does Multinet or VMS provide some way to do this? (Removing NETMBX privilege
whacks DECnet as well as IP - too big a hammer for my uses.)

Thanks,

-- Alan
--
===============================================================================
Alan Winston --- ***@SSRL.SLAC.STANFORD.EDU
Disclaimer: I speak only for myself, not SLAC or SSRL Phone: 650/926-3056
Paper mail to: SSRL -- SLAC BIN 99, 2575 Sand Hill Rd, Menlo Park CA 94025
===============================================================================
Jeremy Begg
2007-03-12 23:38:50 UTC
Permalink
Hi Alan,
Post by Alan Winston - SSRL Central Computing
$multinet show /version
Process Software MultiNet V5.1 Rev A-X, COMPAQ AlphaServer DS20E 666 MHz,
OpenVMS AXP V8.3
I have an account that should be allowed inbound/outbound DECnet access, but
should only be allowed inbound TCP/IP access. (That is, you should be able
to SSH into it, but not, say, launch Xwindows keystroke sniffers from it.)
Does Multinet or VMS provide some way to do this? (Removing NETMBX privilege
whacks DECnet as well as IP - too big a hammer for my uses.)
The only thing which springs to mind would be an ACL on
MULTINET:MULTINET_SOCKET_LIBRARY.EXE but this probably won't to much for
programs which make their own $QIO calls. It would probably defeat most
ported Unix utilities, though.

Regards,

Jeremy Begg

+---------------------------------------------------------+
| VSM Software Services Pty. Ltd. |
| http://www.vsm.com.au/ |
| "OpenVMS Systems Management & Programming" |
|---------------------------------------------------------|
| P.O.Box 402, Walkerville, | E-Mail: ***@vsm.com.au |
| South Australia 5081 | Phone: +61 8 8221 5188 |
|---------------------------| Mobile: 0414 422 947 |
| A.C.N. 068 409 156 | FAX: +61 8 8221 7199 |
+---------------------------------------------------------+

Loading...