Unix Technical Forum

Honeyd on firewall machine ?

This is a discussion on Honeyd on firewall machine ? within the comp.unix.bsd.openbsd.misc forums, part of the OpenBSD category; --> Is it folly to run honeyd on a firewall machine ? I see comments to the effect that one ...


Go Back   Unix Technical Forum > Unix Operating Systems > OpenBSD > comp.unix.bsd.openbsd.misc

Register FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-16-2008, 06:06 AM
George Pontis
 
Posts: n/a
Default Honeyd on firewall machine ?

Is it folly to run honeyd on a firewall machine ? I see comments to the effect
that one should not do this since a honeypot will be interacting with hostile
agents. But the firewall logs show that the firewall is interacting with hostile
agents all the time.

While I do separate the mail and other servers in a small business environment, I
am comfortable running spamd on the firewall and watch the log with some interest.
Could I reasonably do the same with honeyd in a systrace sandbox ?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 02-16-2008, 06:06 AM
erik
 
Posts: n/a
Default Re: Honeyd on firewall machine ?

George Pontis wrote:

> Is it folly to run honeyd on a firewall machine ? I see comments to
> the effect that one should not do this since a honeypot will be
> interacting with hostile agents. But the firewall logs show that the
> firewall is interacting with hostile agents all the time.


But a firewall should not run services. Any services. Certainly not
supposedly vulnerable services. That is plain stupid.

>
> While I do separate the mail and other servers in a small business
> environment, I am comfortable running spamd on the firewall and watch
> the log with some interest. Could I reasonably do the same with honeyd
> in a systrace sandbox ?


Use a machine in a dmz, safely contained...

EJ
--
Remove the obvious part (including the dot) for my email address.
http://www.vanwesten.net for examples of ipf and pf.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 10:58 PM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com