[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

blocking access using ipsec on AIX...

Posted on 2012-03-29
7
Medium Priority
?
1,899 Views
Last Modified: 2012-03-29
ok, this is very simple in linux, but not sure on aix...

I have an AIX box with two ethernet, en0 and en1 on two different vlans, so I want, if possible, to:

Permit  access ANY-IN/OUT on ent0
Permit access ONLY from some IPs to ent1

No need to filter tcp or udo ports, only IP filter is needed.

Possible?

Thanks.
0
Comment
Question by:sminfo
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
7 Comments
 
LVL 68

Expert Comment

by:woolmilkporc
ID: 37780680
Hi again,

IPSEC on AIX is in the bos.net.ipsec.* filesets.

The IPSEC config is best done via "smitty ipsec4".

Go to "Advanced ..." and "Configure IP Security Filter Rules".

"Add an IP Security Filter Rule" by filling in the required fields, including source addresses and interface.

Don't forget to activate the IP security device. Use "smitty ips4_start_stop" for this.

Good luck!

wmp
0
 

Author Comment

by:sminfo
ID: 37780693
and that's it??  :-)
0
 
LVL 68

Expert Comment

by:woolmilkporc
ID: 37780698
Yep,

if you don't want/need advanced stuff like (IKE) VPN tunnels - that's it.

wmp
0
What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

 

Author Comment

by:sminfo
ID: 37780702
wmp, any idea on how to setup ipsec to run on startup? Or it's enable by default?
0
 
LVL 68

Accepted Solution

by:
woolmilkporc earned 2000 total points
ID: 37780737
Once enabled it's present after reboot. You must explicitly disable it to get rid of the beast.

Try  "smitty ips4_start".

You'll see a choice between "Now and After Reboot" and "After Reboot". "Now" alone isn't even possible.

wmp
0
 

Author Closing Comment

by:sminfo
ID: 37780772
nice!!

But I think once you have enabled ipsec on one ethernet interfase, you have to add rules, in this case OPEN, for the other one ethernet, isn't it?
0
 
LVL 68

Expert Comment

by:woolmilkporc
ID: 37781000
You don't need such a rule, but you can configure one, if you like.

Just fill all "IP" fields with "0.0.0.0", specify the interface, leave the rest at default, including, of course, "permit" beneath "Rule Action".

Don't forget to activate updated/added rules with "/usr/sbin/mkfilt -v 4 -u" or "smitty ips4_upd_filter" -> "Activate/Update".

The above rule isn't really necessary, because the default "permit all" rule "0" stays in place. This rule is always the last one in the filter list and cannot be moved away from there. Since the filter list is processed from top to bottom the other, usually more restrictive rules will come first.
0

Featured Post

[Webinar] Lessons on Recovering from Petya

Skyport is working hard to help customers recover from recent attacks, like the Petya worm. This work has brought to light some important lessons. New malware attacks like this can take down your entire environment. Learn from others mistakes on how to prevent Petya like worms.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Installing FreeBSD… FreeBSD is a darling of an operating system. The stability and usability make it a clear choice for servers and desktops (for the cunning). Savvy?  The Ports collection makes available every popular FOSS application and packag…
Introduction Regular patching is part of a system administrator's tasks. However, many patches require that the system be in single-user mode before they can be installed. A cluster patch in particular can take quite a while to apply if the machine…
Learn how to get help with Linux/Unix bash shell commands. Use help to read help documents for built in bash shell commands.: Use man to interface with the online reference manuals for shell commands.: Use man to search man pages for unknown command…
This video shows how to set up a shell script to accept a positional parameter when called, pass that to a SQL script, accept the output from the statement back and then manipulate it in the Shell.
Suggested Courses

656 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question