RE: Binding inetd to ip

From: Ewing, Timothy K. (Timothy.Ewingat_private)
Date: Mon Jan 31 2000 - 13:38:26 PST

  • Next message: Thomas Munn: "How to dump rules on Axent"

    This message is in MIME format. Since your mail reader does not understand
    this format, some or all of this message may not be legible.
    
    ------_=_NextPart_001_01BF6C33.61841EE6
    Content-Type: text/plain;
    	charset="iso-8859-1"
    
    >> Is it possible to bind inetd to a specific ip address/ethernet card under
    >> linux?  I haven't been able to find any info myself, but the reason I
    >> ask is because I currently am running a nameserver that has two network
    >> cards.
    
    >Probably not without hacking inetd. I belive it does a bind to 0.0.0.0,
    which effectively >means "bind to all IPs on the system." You'd have to
    change it to bind to a specific >interface, which is probably not all that
    difficult to do.
    
    I was faced with a similar problem/desire on a home firewall (Linux RH 6.1
    and TIS FWTK) 
    and I remember reading about a program several years ago (the development of
    it has picked
    up lately) called xinetd.  Xinetd uses a file called xinetd.conf and has a
    little script called "itox" to convert inetd.conf syntax to xinetd.conf
    syntax.  It is used to bind 
    specific services to IP addresses.  So for example I have all my proxies for
    the FWTK bound
    to the internal interface, and nothing for the external.  Go the following
    site to get 
    source and information.
    
    	http://synack.net/xinetd
    
    --
    ============================================================================
    ============
    Timothy K. Ewing
    Timothy.Ewingat_private
    Security Analyst                                                    (240)
    453-3091 phone
    Celera Genomics, A PE Corporation Business                          (240)
    453-3305 fax
    
    
    ------_=_NextPart_001_01BF6C33.61841EE6
    Content-Type: text/html;
    	charset="iso-8859-1"
    Content-Transfer-Encoding: quoted-printable
    
    <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
    <HTML>
    <HEAD>
    <META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
    charset=3Diso-8859-1">
    <META NAME=3D"Generator" CONTENT=3D"MS Exchange Server version =
    5.5.2650.12">
    <TITLE>RE: Binding inetd to ip</TITLE>
    </HEAD>
    <BODY>
    
    <P><FONT SIZE=3D2>&gt;&gt; Is it possible to bind inetd to a specific =
    ip address/ethernet card under</FONT>
    <BR><FONT SIZE=3D2>&gt;&gt; linux?&nbsp; I haven't been able to find =
    any info myself, but the reason I</FONT>
    <BR><FONT SIZE=3D2>&gt;&gt; ask is because I currently am running a =
    nameserver that has two network</FONT>
    <BR><FONT SIZE=3D2>&gt;&gt; cards.</FONT>
    </P>
    
    <P><FONT SIZE=3D2>&gt;Probably not without hacking inetd. I belive it =
    does a bind to 0.0.0.0, which effectively &gt;means &quot;bind to all =
    IPs on the system.&quot; You'd have to change it to bind to a specific =
    &gt;interface, which is probably not all that difficult to =
    do.</FONT></P>
    
    <P><FONT SIZE=3D2>I was faced with a similar problem/desire on a home =
    firewall (Linux RH 6.1 and TIS FWTK) </FONT>
    <BR><FONT SIZE=3D2>and I remember reading about a program several years =
    ago (the development of it has picked</FONT>
    <BR><FONT SIZE=3D2>up lately) called xinetd.&nbsp; Xinetd uses a file =
    called xinetd.conf and has a little script called &quot;itox&quot; to =
    convert inetd.conf syntax to xinetd.conf syntax.&nbsp; It is used to =
    bind </FONT></P>
    
    <P><FONT SIZE=3D2>specific services to IP addresses.&nbsp; So for =
    example I have all my proxies for the FWTK bound</FONT>
    <BR><FONT SIZE=3D2>to the internal interface, and nothing for the =
    external.&nbsp; Go the following site to get </FONT>
    <BR><FONT SIZE=3D2>source and information.</FONT>
    </P>
    
    <P>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <FONT SIZE=3D2><A =
    HREF=3D"http://synack.net/xinetd" =
    TARGET=3D"_blank">http://synack.net/xinetd></FONT>
    </P>
    
    <P><FONT SIZE=3D2>--</FONT>
    <BR><FONT =
    SIZE=3D2>=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
    =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
    =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
    =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D</FONT>
    <BR><FONT SIZE=3D2>Timothy K. =
    Ewing&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
    nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
    nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
    nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
    Timothy.Ewingat_private</FONT>
    <BR><FONT SIZE=3D2>Security =
    Analyst&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
    ;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
    ;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
    ;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
    ;&nbsp;&nbsp;&nbsp;&nbsp; (240) 453-3091 phone</FONT>
    <BR><FONT SIZE=3D2>Celera Genomics, A PE Corporation =
    Business&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
    p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
    p;&nbsp;&nbsp; (240) 453-3305 fax</FONT>
    </P>
    
    </BODY>
    </HTML>
    ------_=_NextPart_001_01BF6C33.61841EE6--
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 13:59:47 PDT