Craig,
Can you send the log file to support@open-e.com on the subject line please enter
RefID#10004850 for the ticket that we have created for you.
Thanks!
Craig,
Can you send the log file to support@open-e.com on the subject line please enter
RefID#10004850 for the ticket that we have created for you.
Thanks!
Hi Todd. Which log file do you want me to send to support? The portscan that I posted or something from the Open-E box?
Craig
im a minimalist which is why i bought open-e ISCSI. but instead i get all the bloat of DSS without the functionality.
dont you think that removing these un-needed services may help the performance and stability of the system?
looks like open-e is also using the default debian etch kernel?
Not sure what the complaint is DSS or iSCSI-R3? What are the un-needed services you are referring to - need details? Then we can ask others what their opinions are as well. We are looking into giving more control to the user on some of these services but at a later date. And yes we are using debian etch, this is easy to identify with the logs. What distros have you developed or have tested with results? Need more details to support the use of your discussion.
heres my nessus summary, if you want the actual report let me know:Originally Posted by To-M
unknown (842/tcp)
https (443/tcp)
vampire (6669/tcp)
unknown (25456/tcp)
irc-serv (6666/tcp)
unknown (4702/tcp)
unknown (11798/tcp)
vocaltec-gold
unknown (25457/tcp)
ircd (6667/tcp)
netbios-ssn (139/tcp)
sunrpc (111/tcp)
http (80/tcp)
iscsi-target (3260/tcp)
microsoft-ds (445/tcp)
ldap (389/tcp)
irc (6668/tcp)
prosiak (22222/tcp)
cddbp (888/tcp)
sunrpc (111/udp)
unknown (840/udp)
netbios-ns (137/udp)
ntp (123/udp)
Thats the open ports on a iscsi-r3 box. The only things I'm expecting are 3260 and 22222!
possible that Xinetd is enabled? why would I see IRC!
ok we have been pen-testing this since last night (mini hackathon lol) and what i have initially found is that there is no way to access these services - which is what i expected.
what i really wanted to hint at for this wasnt that we didnt trust that they were configured properly by open-e; just that if i purchase an ISCSI-R3 product im still running all these DSS'ish services
so in the food chain all dev work is done on DSS then flows out to ISCSI product, maybe before putting the "big red bow" on the ISCSI-R3 product, they could for example:
"/etc/init.d/samba stop" etc. etc.
make sense? its really the only difference in my performance variances between gentoo (my bootstrapped, hand built iscsi box which took 4 hours to get set up) and open-e. i have 2 ports open in gentoo - 3260,22it was only about a 2% difference in performance and that small of a difference is completely trivial when you are talking about something that peaks at 128mb/s on a single gbe link.