Re: restrict remote access
Posted in 1999
On Friday 19th March 1999, Sergey Tsvetukhin <tsv@nb.udmnet.ru> asked: >I want to restrict remote access to Informix universal server (v.9.14, >Solaris 2.6) > >I want to have tools like tcp_wrapper. >tcp_wrapper cannot be use becouse _Informix_ listen port > >Question: >1. Can I run Informix services throw inetd ? I think not, but stand to be corrected. AFAIK, daemons have to be designed to work under inetd, and sqlexecd isn't designed to work under sqlexecd. This affects Informix-SE and I-Star in 5.x systems. Additionally, as you say, IDS and IDS/UDO (IUS) listen directly to the port they're commanded to listen to. Consequently, there's no direct way to have inetd mediate the connections. I'm not sure whether you could fake it by having IDS/UDO listen on some undocumented port, and then have a special inetd/tcp_wrapper daemon validate the connection and fork off a process which did some sort of loopback connection, relaying information between the publicly available validated port and the private undocumented port. Since there's an extra process in the loop, performance would be an issue. >2. Can I restrict access to port from others machine in my subnet ? Up to a point. If you ensure that the machine only recognizes other machines in your subnet as trusted, then people connecting from outside the subnet will have to provide username and password information in a CONNECT statement. If those people don't have valid login entries on the server, they will be denied access. Yours, Jonathan Leffler (jleffler@informix.com) #include <wish/I/was/skiing.h> Guardian of DBD::Informix v0.60 (v0.61_02) -- http://www.perl.com/CPAN Informix IDN for D4GL & Linux -- http://www.informix.com/idn