Managing Files
When you run dcbsyssecurity.sh, the system displays this menu:
1) High Security With SSH. Disable all the unsecured Unix services* but leave sshd
running.
2) High Security Without SSH. Disable all the unsecured Unix services* and sshd
3) Enable/Disable Individual Services. Displays a sub-menu that allows you to select
an option to DISABLE or ENABLE a service.
1) Service systat is ENABLED
2) Service netstat is ENABLED
3) Service telnet is ENABLED
4) Service finger is ENABLED
5) Service i2odialog is ENABLED
6) Service exec is ENABLED
7) Service login is ENABLED
8) Service shell is ENABLED
9) Quit
4) Reset. Enable all the unsecured Unix services* and sshd. (back to the system
default setting)
5) Quit
* : Includes filtering out ICMP timestamp request and reply. The following is an example for
configuring a filtering condition in /etc/pf.d/IP/net0 for interface net0. It may be merged with any
existing filtering conditions. It also has to apply to all the IP network interfaces.
# Don't allow request and reply timestamp of ICMP
blockicmp
# empty filter
noblockicmp
Additional Information About File Transfers
This section discusses file naming standard for cross-platform file transfers and how to create
various system files offline for downloading.
DOS and UNIX Filenames
The system's UNIXWARE operating system permits mixed case file names (all upper-case, all
lower-case, or a combination of cases). When transferring UNIXWARE files to a DOS computer
(using ftp or rcp) or exporting files, file names are forced to all upper-case letters. When you
restore these files using a LAN transfer, file names may be forced to lower-case or upper-case,
depending on the particular ftp or rcp software you use. Therefore, advise all personnel creating
files to use fully unique file names; vary the characters, not just the case. Thus, file names
"ACME," "Acme," "acme" are unacceptable, but "ACME1," "Acme2," "acme3" are fine, and
"acme1," "acme2," "acme3" are even better.
246 Administration and Maintenance of the CS700/CS780 Audio Conferencing Server
!(icmp[0] == 13 or icmp[0] == 14)