store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Thu May 23, 2013 5:10 am

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 9 posts ] 
Author Message
 Post subject: hi, auditor says we need to block DMZ's egress by default
Unread postPosted: Thu Aug 16, 2012 9:11 pm 
Offline
Forum User
Forum User

Joined: Mon Jun 11, 2012 1:10 pm
Posts: 53
Location: usa
i'm faced w/ a bit of a dilemma here.
i've purchased ASL in hopes that it will make our life a bit easier for PCI-compliance. (and it has!)
but now it just comes to our realization that, DMZ of the servers need egress blocked (to internet) to meet pci compliance.
this poses a bit of a challenge and i'm not sure what to do here.
my thoughts were that we can whitelist your ip's along w/ other services ASL uses, but i do not know where to start for that.

any advice you guys can provide?
time is starting to be a bit critical here :X


Top
 Profile  
 
 Post subject: Re: hi, auditor says we need to block DMZ's egress by defaul
Unread postPosted: Fri Aug 17, 2012 8:31 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7425
Location: earth
a proxy server is an option there


Top
 Profile  
 
 Post subject: Re: hi, auditor says we need to block DMZ's egress by defaul
Unread postPosted: Fri Aug 17, 2012 12:49 pm 
Offline
Forum User
Forum User

Joined: Mon Jun 11, 2012 1:10 pm
Posts: 53
Location: usa
are there any IP address that you guys can provide, so I can just whitelist as a quick solution for now?
and i thought about proxy but how would i configure ASL so that my servers will start communicating to proxy? this would be a great solution, just, i'm not sure how complex this would be.


Top
 Profile  
 
 Post subject: Re: hi, auditor says we need to block DMZ's egress by defaul
Unread postPosted: Fri Aug 17, 2012 4:08 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7425
Location: earth
The proxy code (aum) is in alpha right now, and the IP to whitelist are:
74.208.155.133
74.208.166.51
74.208.97.167
208.68.233.251
74.208.195.110
69.20.6.166


Top
 Profile  
 
 Post subject: Re: hi, auditor says we need to block DMZ's egress by defaul
Unread postPosted: Fri Aug 17, 2012 6:44 pm 
Offline
Forum User
Forum User

Joined: Mon Jun 11, 2012 1:10 pm
Posts: 53
Location: usa
great thank you!


Top
 Profile  
 
 Post subject: Re: hi, auditor says we need to block DMZ's egress by defaul
Unread postPosted: Fri Aug 17, 2012 7:53 pm 
Offline
Forum User
Forum User

Joined: Mon Jun 11, 2012 1:10 pm
Posts: 53
Location: usa
Sorry, but could you also list the ports too associated w/ those IPs?


Top
 Profile  
 
 Post subject: Re: hi, auditor says we need to block DMZ's egress by defaul
Unread postPosted: Sat Aug 18, 2012 1:18 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
443

You may need 53 as well, so you can lookup the FQDNs for the servers. If you cant do that, then you will need to create /etc/hosts records for:

www.atomicorp.com
updates.atomicorp.com

We recommend you use DNS, as new IPs are added as we add more mirror servers.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: hi, auditor says we need to block DMZ's egress by defaul
Unread postPosted: Sat Aug 18, 2012 5:47 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7425
Location: earth
also 25 and 465 for mail


Top
 Profile  
 
 Post subject: Re: hi, auditor says we need to block DMZ's egress by defaul
Unread postPosted: Mon Aug 20, 2012 1:46 pm 
Offline
Forum User
Forum User

Joined: Mon Jun 11, 2012 1:10 pm
Posts: 53
Location: usa
awesome, thx


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 9 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group