Re: restrict remote access
Posted in 1999
On Mon, Mar 29, 1999 at 12:50:54PM -0800, Jonathan Leffler wrote: > On Friday 19th March 1999, Sergey Tsvetukhin <tsv@nb.udmnet.ru> asked: > >I want to restrict remote access to Informix universal server (v.9.14, > >Solaris 2.6) > > > >I want to have tools like tcp_wrapper. > >tcp_wrapper cannot be use becouse _Informix_ listen port > > > >Question: > >1. Can I run Informix services throw inetd ? > > I think not, but stand to be corrected. AFAIK, daemons have to be designed > to work under inetd, and sqlexecd isn't designed to work under sqlexecd. > This affects Informix-SE and I-Star in 5.x systems. Additionally, as you > say, IDS and IDS/UDO (IUS) listen directly to the port they're commanded to > listen to. Consequently, there's no direct way to have inetd mediate the > connections. > > I'm not sure whether you could fake it by having IDS/UDO listen on some > undocumented port, and then have a special inetd/tcp_wrapper daemon > validate the connection and fork off a process which did some sort of > loopback connection, relaying information between the publicly available > validated port and the private undocumented port. Since there's an extra > process in the loop, performance would be an issue. > It was a question like this in the newsgroup some time ago. Why don't configure Informix to listen just on 'localhost', i.e. 127.0.0.1. Then you can write a small program that can be put in inetd and on a user connection just perform a subsequent connection to informix port on localhost. Then, you can controll the access to this connection through tcp_wrapper. I didn't try it but this should work. Best Regards, Octav -- Octav Chiriac Phone: (373) 2 21 20 96 NetInfo S.R.L. Fax: (373) 2 21 36 59 Chisinau (373) 2 24 00 83 Moldova, Republic of mailto:com@netinfo-moldova.com