Securing syslog for a subnet

From: John Horne (J.Horne@plymouth.ac.uk)
Date: Fri Jul 12 2002 - 04:31:21 EDT


Hello,

We have previously only run syslog locally on the Sun systems - i.e. a local
syslog only received local messages. However, we now want one system to
receive syslog messages from other systems within the University. No problem
since the Suns will do this - the 't/-T' switches. However, how can I secure
the syslog process to only receive messages within the University's subnet?
What is to prevent someone from simply sending loads of syslog messages to a
system and potentially creating a DoS. Not sure that would happen (the DoS),
but it seems possible. What I would like to do, in effect, put TCP wrappers
around syslog as we do with other services.

Anyone any ideas about this? This will be on a Sun Ultra 10 with Solaris 9.

Regards,

John.

------------------------------------------------------------------------
John Horne, University of Plymouth, UK Tel: +44 (0)1752 233914
E-mail: jhorne@plymouth.ac.uk
PGP key available from public key servers
_______________________________________________
sunmanagers mailing list
sunmanagers@sunmanagers.org
http://www.sunmanagers.org/mailman/listinfo/sunmanagers



This archive was generated by hypermail 2.1.7 : Wed Apr 09 2008 - 23:24:35 EDT