26
3.4 System Service Access
ServiceAccessspecieswhichaccessprotocols/servicescanbeusedtoaccesstheConsoleServer(andconnectedserialports).
TheAdministratorcanaccessandconguretheConsoleServer(andconnecteddevices)usingarangeofaccessprotocols/
services–andforeachsuchaccess,theparticularservicemustberunningwithaccessthroughtherewallenabled.
BydefaultHTTP,HTTPS,TelnetandSSHservicesarerunning,andtheseservicesareenabledonallnetworkinterfaces.However,
againbydefault,onlyHTTPSandSSHaccesstotheConsoleServerisenabled,whileHTTPandTelnetaccessisdisabled.
Forotherservices,suchasSNMP/NagiosNRPE/NUT,theservicemustrstbestartedontherelevantnetworkinterfaceusing
PortRules(referChapter5.7).ThentheServicesAccesscanbesettoalloworblockaccess.
To change the access settings:
• SelecttheService Access tab on the System: Firewall page. This will displays the services currently enabled for the
ConsoleServer’snetworkinterfaces.DependingontheparticularConsoleServermodeltheinterfacesdisplayedmay
include :
o Networkinterface(fortheprincipalEthernetconnection)
o Dialout(V90andcellularmodem)
o Dialin(internalorexternalV90modem)
o WiFi(802.11wireless)
o OoBFailover(secondEthernetconnections)
o VPN(IPSecorOpenVPNconnectionoveranynetworkinterface)
• Check/uncheckforeachnetworkwhichserviceaccessistobeenabled/disabled
IntheexampleshownbelowlocalAdministratorsonlocalNetworkInterfaceLANdonothaveTelnetaccesstotheConsole
Serveritself(onlySSHandHTTPSaccess)buttheydohaveTelnetaccesstotheserialconsoledevicesattachedtothe
consoleServer.SimilarlyremoteAdministratorsusingDialInonlycanaccesstheNagios/NUTstatusfromtheconsoleServer
whileVPNconnectedAdministratorshavebeengivenextensiveservicesaccess.
Chapter 3: Initial System Configuration