| |
# This is ssh server systemwide configuration file.
Port 22
# avoid SSHv1 subjected to several vulnerabilities
Protocol 2,1
# when you copy this file for your jail to use think of putting
# here alias your jail.
ListenAddress 127.0.0.1, public_IP, jail_IP
HostKey /etc/ssh/ssh_host_key
HostKey /etc/ssh/ssh_host_rsa_key
HostKey /etc/ssh/ssh_host_dsa_key
ServerKeyBits 768
LoginGraceTime 60
KeyRegenerationInterval 3600
RhostsAuthentication no
RSAAuthentication yes
PubkeyAuthentication yes
# preferred order of the authentification and encryption algorithms
Ciphers blowfish-cbc,aes256-cbc,aes192-cbc,aes128-cbc,3des-cbc,cast128-cbc,arcfour
MACs hmac-sha1,hmac-md5,hmac-ripemd160,hmac-sha1-96,hmac-md5-96
# sending of a message after an interval given
# and deconnexion after several sendings
KeepAlive yes
ClientAliveInterval 30
ClientAliveCountMax 5
# to avoid the imitations flooding A of the repeated attempts at connection,
# we install a kind of quotas on the level of the management of connections.
# 10 for the number of connections not auhentifiees, 40 for the percentage of
# refusal after the first number reached, and 50 meaning that at the end of 50
# tentative any connection not authentifiee is refusee.
MaxStartups 10:40:50
# here we eliminate the vulnerabilites dregs with the files ~/.rhosts and
# ~/.shosts and has their relations of confidence.
IgnoreRhosts yes
# verifier permissions and ownership of the files and of/home before accepting
# a login
StrictModes yes
X11Forwarding no
X11DisplayOffset 10
PrintMotd yes
# Syslog
SyslogFacility AUTH
LogLevel DEBUG
# Below us privilegions the use of cles RSA and DSA for
# authentification instead of the password
PasswordAuthentication no
# if you choississez to put the preceding option has yes, add that below
# to prohibit passwords empty
# PermitEmptyPasswords No
# decontaminates the authentification s/key
SkeyAuthentication No
KbdInteractiveAuthentication yes
ChallengeResponseAuthentication No
# these blocks are relative has authentification Kerberos
# KerberosAuthentication No
# KerberosOrLocalPasswd yes
# AFSTokenPassing No
# KerberosTicketCleanup No
# Kerberos TGT Passing does only work with the AFS kaserver
# KerberosTgtPassing yes
PermitRootLogin no
CheckMail yes
UseLogin yes
# we do not recommend it because of its relative experimentalite but this
# line allows you the case echeant to use sftp.
# Subsystem sftp/usr/libexec/sftp-server
# facility destination
*.=<notice /var/log/messages
*.=<crit root
auth,authpriv.* /var/log/authlog
cron.info /var/log/cron
mail.info /var/log/maillog
kern.* /var/log/kernel
security.* /var/log/security
security.=<err /dev/console
!ppp
*.* /var/log/ppp.log
!ipfw
*.* /var/log/ipfw.log
!sudo
*.* /var/log/sudo.log
!racoon
*.* /var/log/racoon.log
!nessusd
*.* /var/log/nessus.log
!argus
*.* /var/log/argus.log
# configuration syslog to be added in the jail
#!apache
#*.* /var/log/access_log
#!bind
#*.* /var/log/named
# logfilename [owner:group] mode count size time flags
/var/log/maillog 440 10 * @T00 J
/var/log/messages 440 15 100 * J
/var/account/acct 440 15 * @T00 J
/var/log/cron 440 10 40 * J
/var/log/ppp.log 440 10 40 * J
/var/log/nessus.log 440 10 40 * J
/var/log/alias.log 440 10 40 * J
/var/log/authlog root:wheel 400 10 20 @T00 J
/var/log/security root:wheel 400 10 20 @T00 J
/var/log/ipfw.log root:wheel 400 10 20 @T00 J
/var/log/sudo.log root:wheel 400 10 20 @T00 J
/var/log/racoon.log root:wheel 440 10 20 * J
#/var/log/access_log www:wheel 1440 10 40 * J
#/var/log/named named:wheel 1440 10 40 * J
/var/log/wtmp 440 15 * @01T01 B
# you have the possibility of specifier with which Shell executer the orders
SHELL=/bin/sh
# this option makes it possible to indicate has cron which to prevenir in the event of problem
MAILTO=root
#
# update of the plugins Nessus each week
@weekly nessus-update-plugins
# checking of integrite mtree every week
@weekly mtree -x -i -f bin.spec | mail -s 'mtree /bin \
results' root
@weekly mtree -x -i -f sbin.spec | mail -s 'mtree /sbin \
results' root
@weekly mtree -x -i -f libexec.spec | mail -s 'mtree \
/usr/libexec results' root
@weekly mtree -x -i -f lib.spec | mail -s 'mtree /usr/lib \
results' root
@weekly mtree -x -i -f sharelib.spec | mail -s 'mtree \
/usr/share/lib results' root
@weekly mtree -x -i -f boot.spec | mail -s 'mtree /boot \
results' root
# accompanied by a checking of the services by lsof
@weekly lsof -niU
# and of a checking KSEC
@daily ksec -i interface -b -k -p
# update ports tree only for the environment host
@monthly make update PORTSFILE
# newsyslog
@hourly newsyslog
# ntpdate daily if you have significant uptimes
@daily ntpdate ntp-sop.inria.fr
# launching of racoon to starting
@reboot racoon -f /etc/racoon.conf
# variables ...
fwcmd="ipfw -q"
net="192.168.0.0"
mask="255.255.255.0"
jail="192.168.0.2"
intif="fxp0"
extif="fxp1"
${fwcmd} -f flush
# reserved addresses
${fwcmd} add 201 deny log all from 192.168.0.0/16,172.16.0.0/12,10.0.0.0/8,
127.0.0.0/8,0.0.0.0/8,169.254.0.0/16,192.0.2.0/24,204.152.64.0/23,
224.0.0.0/3,${net}:${mask} to any in via ${extif}
# divert towards natd
${fwcmd} add 300 divert 8668 all from any to any in via ${extinf}
# checking compared to the state table
${fwcmd} add 400 check-state
${fwcmd} add 401 deny tcp from any to any in established
${fwcmd} add 402 deny ip from any to any in frag
# communication DNS, SSH, Racoon, Argus and Nessus
${fwcmd} add 403 allow udp from ${net}:${mask} to primary_DNS 53 in keep-state
${fwcmd} add 404 allow tcp from any to me 22 keep-state setup limit src-addr 5
${fwcmd} add 405 allow udp from any 500 to any keep-state
${fwcmd} add 406 allow udp from any to any 500 keep-state
${fwcmd} add 407 allow tcp from any to any 561,3001 keep-state limit dst-addr 2
# communications towards traditional waiters
${fwcmd} add 408 allow tcp from ${net}:${mask} to any
20,21,22,25,80,110,123,143,443,994,995,6667 keep-state setup
# limitations ICMP (ping, Van Jacobson' S traceroute...)
${fwcmd} add 500 allow icmp from any to ${net}:${mask} in icmptypes 0,3,11,12,13,14
${fwcmd} add 501 allow icmp from ${net}:${mask} to any out icmptypes 1,8,11
${fwcmd} add 502 allow udp from ${net}:${mask} to any in 33400-33500
${fwcmd} add 503 deny log icmp from any to any
# redirection services jail
${fwcmd} add 602 allow udp from any to ${jail} 53 in keep-state via lo0
${fwcmd} add 603 allow tcp from any to ${jail} 80,443 in keep-state setup via lo0
# Restrictive stanza: everything not explicitely allowed is forbidden.
${fwcmd} add 900 deny log all from any to any
${fwcmd} add 901 deny log all from any to ${jail} via lo0
log yes
deny_incoming no
use_sockets yes # allocate a socket limiting the conflicts of ports
# dynamic
same_ports yes # try to use the same port for the translation
verbose no
port natd
unregistered_only yes # NAT only for the addresses type RFC 1918
log_ipfw_denied yes # log packages not reinjected due to
# blocking by ipfw (useful for debugger)
# DNS
redirect_port udp jail_IP_alias:53 public_IP_adress:53
# HTTP or HTTPS
# LSNAT > RFC 2391
redirect_port tcp jail_IP_alias:80,443 80,443
redirect_adress tcp www1_IP:80, www2_IP:80 jail_IP_adress:80
# SSH on the second jail
redirect_port tcp jail_user_IP_alias:22
# static NAT for other machines
redirect_address internal_IP1 public_IP
redirect_address internal_IP2 public_IP
redirect_address internal_IP3 public_IP