During the Manager installation, configurational scripts are run automatically to harden the operating system as a best practice. After the configuration, only the ports required for communication between the Manager and point integrations, such as Sensor, ePolicy Orchestrator, and Alert Service, are open. The communication on the non-essential ports is disabled.
Reconfiguration of SSH
After running the configuration script, the SSH configuration file contains the following configuration:
| Configuration | Comments |
|---|---|
| Protocol 2 | Use of protocol version 1 is not recommended. It may be susceptible to man-in-the-middle attacks. |
Ciphers
|
Use of strong cipher suites to make the encryptions better. The MAC (Message Authentication Code) algorithm is used in protocol version 2 for data integrity protection. Multiple algorithms must be comma-separated. |
Reconfiguration of SSHD
After running the configuration script, the SSHD configuration file contains the following configuration:
| Configuration | Comments |
|---|---|
| Port 22 | Used for SSH communication |
| Protocol 2 | Use of protocol version 1 is not recommended. It may be susceptible to man-in-the-middle attacks. |
| HostKey /etc/ssh/ssh_host_dsa_key | Specifies a file containing a private host key used by SSH |
| RekeyLimit 1G 1h | The first argument specifies the maximum amount of data that can be transmitted before the session key is renegotiated. The second argument, which is optional, specifies the maximum amount of time that may pass before the session key is renegotiated. The first argument is specified in bytes and may have a suffix of K, M, or G to indicate Kilobytes, Megabytes, or Gigabytes, respectively. |
| SyslogFacility AUTH | Specifies the facility code that is used when logging messages from sshd. The default value is AUTH |
| LogLevel VERBOSE | Specifies the verbosity level that is used when logging messages from sshd |
Ciphers
|
Use of strong cipher suites to make the encryptions better. The MAC (Message Authentication Code) algorithm is used in protocol version 2 for data integrity protection. Multiple algorithms must be comma-separated. |
| LoginGraceTime 300 | Specifies the time limit after which the server disconnects if the user is not successfully logged in |
| PermitRootLogin no | Specifies whether the root user can log in using ssh. The default value is yes. |
| StrictModes yes | Specifies whether sshd should check file modes and ownership of the user's files and home directory before accepting login. The default value is no. |
| MaxAuthTries 3 | Specifies the maximum number of authentication attempts permitted per connection |
| HostbasedAuthentication no | Specifies whether rhosts or /etc/hosts.equiv authentication together with successful public key client host authentication is allowed. |
| IgnoreUserKnownHosts yes | Specifies whether sshd should ignore the user's ~/.ssh/known_hosts during RhostsRSAAuthentication or HostbasedAuthentication |
| AllowAgentForwarding no | Specifies whether ssh-agent forwarding is permitted |
| AllowTcpForwarding no | Specifies whether TCP forwarding is permitted |
| X11Forwarding no | Specifies whether X11 forwarding is permitted |
| PrintMotd yes | Specifies whether sshd should print /etc/motd when a user logs in interactively |
| TCPKeepAlive yes | Specifies whether the system should send TCP keepalive messages to the other side. The default is yes (to send TCP keepalive messages), and the server will notice if the network goes down or the client host crashes. This avoids infinitely hanging sessions. |
| MaxStartups 3 | Specifies the maximum number of concurrent unauthenticated connections to the SSH daemon. Additional connections will be dropped until authentication succeeds or the LoginGraceTime expires for a connection. |
| Banner /etc/legal | The contents of the specified file are sent to the remote user before authentication is allowed. |
| Subsystem sftp /usr/libexec/sftp-server (modified from Subsystem sftp /usr/libexec/openssh/sftp-server) | Configures an external subsystem, such as a file transfer daemon. Arguments should be a subsystem name and a command to execute upon subsystem request. The sftp-server command implements the SFTP file transfer subsystem. |
Reconfiguration of IP tables, and ports used by the Manager and Sensor, integrated products, and other third-party applications for communications
For more information on the IP Table configuration after running the reconfiguration script, ports and traffic destinations as used by the Manager and Sensor, and ports used by third-party applications and integrated products, such as NTBA, Intelligent Sandbox, ePO, MVX etc., refer to the section Set the desktop firewall.
For information of how to disable or enable firewall ports in MLOS, refer to the section Steps to disable or enable ports on firewall in MLOS in Trellix Intrusion Prevention System Manager Appliance Product Guide.