Database firewall
Posted in 2015
Topics: Platform-Specific Issues
Hi, Anyone knows any tool or software (compatible with Informix) to be used as database firewall? We want only certain machines to connect to a database server. The source machines may be of different operating systems (Windows, Linux, HPUX). The database server runs in a HP-UX 11i v3 box. HPUX IPfilter would be enough? Is there a better tool? I had heard of Guardium and Imperva, but I think they do not have the functionality to restrict by source IP addresses. Please provide any clues according your experience. Thanks Roger
Roger: Assuming that your Informix is running on some flavor of UNIX, you already have the tools in the engine itself. If you are using the default authentication, then just correctly configure the /etc/hosts.allow and /etc/hosts.deny files or the Informix equivalent control files to restrict authentication to permitted hosts. Art Art S. Kagel, President and Principal Consultant ASK Database Management www.askdbmgt.com Blog: http://informix-myview.blogspot.com/ Disclaimer: Please keep in mind that my own opinions are my own opinions and do not reflect on the IIUG, nor any other organization with which I am associated either explicitly, implicitly, or by inference. Neither do those opinions reflect those of other individuals affiliated with any entity with which I am affiliated nor those of the entities themselves. On Tue, May 12, 2015 at 10:16 PM, ROGER VILCA <rvilca@luzdelsur.com.pe> wrote: > Hi, > Anyone knows any tool or software (compatible with Informix) to be used as > database firewall? > We want only certain machines to connect to a database server. > > The source machines may be of different operating systems (Windows, Linux, > HPUX). The database server runs in a HP-UX 11i v3 box. > > HPUX IPfilter would be enough? Is there a better tool? > I had heard of Guardium and Imperva, but I think they do not have the > functionality to restrict by source IP addresses. > > Please provide any clues according your experience. > > Thanks > Roger > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > --001a113ea43ec33cdd0515ee3370
Art, Thanks for the reply. My IDS uses the OS login system for user validation. I know that the hosts.allow and hosts.deny files are only used for internet services, with an attempt to login to the server. For example, to allow logon with ssh only for the IP 80.103.12.20: hosts.allow sshd: 80.103.12.20 hosts.deny ALL: ALL How would the case of Informix? Regards, Roger
Works the same way. Informix uses the same authentication method for remote connection requests as rsh, rcmd, and RPCs do. So, if the source host is not allowed or the login user is not allowed from the source host, then login is denied with, IB, a -957 error (code might not be right, going from memory). Art On May 13, 2015 11:51 AM, "ROGER VILCA" <rvilca@luzdelsur.com.pe> wrote: > Art, > Thanks for the reply. > My IDS uses the OS login system for user validation. > I know that the hosts.allow and hosts.deny files are only used for internet > services, with an attempt to login to the server. > For example, to allow logon with ssh only for the IP 80.103.12.20: > > hosts.allow > sshd: 80.103.12.20 > > hosts.deny > ALL: ALL > > How would the case of Informix? > > Regards, > Roger > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > --bcaec5196941fd01470515fcdaee
What you need is a genereci firewall that blocks the Informix port(s) depending on the source... Or you can create generic sysdbopen procedures that check the origin. The files option can prevent trusted connections. They'd be useless for user/password authentication attempts. Guardium can kill connections based on many conditions. The client address is one among those, but the natue of the product it to audit accesses... Not to block them, although it's in the feature lists (how well that works may depend on the database technology and Guardium version). But it would be a waste of money (which we all at IBM would appreciate!) "just" to prevent connections. Regards. On Wed, May 13, 2015 at 4:51 PM, ROGER VILCA <rvilca@luzdelsur.com.pe> wrote: > Art, > Thanks for the reply. > My IDS uses the OS login system for user validation. > I know that the hosts.allow and hosts.deny files are only used for internet > services, with an attempt to login to the server. > For example, to allow logon with ssh only for the IP 80.103.12.20: > > hosts.allow > sshd: 80.103.12.20 > > hosts.deny > ALL: ALL > > How would the case of Informix? > > Regards, > Roger > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently... --001a113d5b880814620515fd74e3