Sharing on a Network / File Server Security
Visitors to VTC.com will be able to view all introductory videos for each training course.
Free Trial Members will gain access to first three chapters for each training course.
Full Access Members have full access to VTC.com’s entire library of video tutorials.
Learn More
Subtitles of the Movie
Let's review the security options associated with fileservers. As described in the related videos for the vsftp, nfs, and samba servers, you could customize some level of security in those individual configuration files, but you can also configure common levels of security for all services. IP tables-based Firewalls can be configured with the Security Level Configuration tool, as you can see in the GUI version of the tool, it looks like you could easily configure trusted services just by clicking the appropriate tick mark. You would think this supports trusted services for fdp, nfs, and samba services, and that's true for ftp and samba, but for nfs, this isn't good enough, as described in the related NFS video. You'll also need to fix the ports for a few daemons related to NFS in the etc slash sysconfig slash nfs file. You could then configure access through those ports using the other ports option and the "at" port window shown here. All of these services are configured using TCP packets, and thus can also be controlled using TCP Wrappers, as configured in the etc slash hosts dot allow and etc slash hosts dot deny configuration files. Let's review a bit from the TCP Wrappers video. Directives in these files are configured in the daemon client command format, and with these directives, the command isn't required. The daemon is normally defined in the user slash sbin directory. For the vsftp server, the daemon is vsftpd. For the nfs server, the daemon is rvc dot nfsd. For Samba, the daemon is smbd. The client can be configured in domain name format. For example, dot example dot net includes all clients with the example dot net suffix. The client can also be configured in IP address format. For example, the ipaddress network mask combination shown here includes all addresses on that private ip network. And, of course, there is Security Enhanced Linux, which is most easily configured with the SELinux Management tool. It provides fine grain control. Configuration details were described in other videos.
Tutorial Information
| Course: | Red Hat Certified Engineer |
| Author: | Michael Jang |
| SKU: | 33845 |
| ISBN: | 1-934743-47-X |
| Release Date: | 2008-01-18 |
| Duration: | 6.5 hrs / 94 lessons |
| Captions: | For Online University members only |
| Compatibility: |
Vista/XP/2000, OS X, Linux QuickTime 7, Flash 8 |
VTC Sign up & Benefits
- Unlimited Access
- 98,729 Video Tutorials (23,265 free)
- Video Available as Flash or QuickTime
- Over 1026 Courses
- $30 for One Month Access
- Multi-User Discounts Available
United States 