SunScreen 3.1 Administration Guide

Preface

SunScreenTM 3.1 for the Solaris Operating environment is part of the family of SunScreen products that provide a solution to security authentication and privacy requirements. SunScreen gives companies a means of securing department networks connected to a public internetwork.

This SunScreen 3.1 Administration Guide provides all the information necessary to configure and administer SunScreen on your network. Other manuals in the SunScreen documentation set include the SunScreen Installation Guide, the SunScreen Reference Manual, the SunScreen Configuration Examples manual, and the SKIP User's Guide.

Who Should Use This Book

The SunScreen 3.1 Administration Guide is intended for SunScreen system administrators responsible for the operation, support, and maintenance of network security. In this guide, it is assumed that you are familiar with UNIX system administration and TCP/IP networking concepts, and with your network topology.

SunScreen 3.1 Lite

SunScreen 3.1 Lite is a stateful, packet-filtering firewall that has a subset of the features in SunScreen 3.1. It protects individual servers and small work groups.

This manual applies to both the SunScreen 3.1 Lite and the full version of SunScreen 3.1. Keep the following difference and similarities in mind when configuring and administering SunScreen 3.1 Lite.

Supported Features

SunScreen 3.1 Lite supports the following SunScreen features. A SunScreen 3.1 Lite firewall:

Limitations

SunScreen 3.1 Lite does not support the following SunScreen features. A SunScreen 3.1 Lite firewall:

How This Guide Is Organized

The SunScreen 3.1 Administration Guide contains the following chapters and appendixes:

Ordering Sun Documents

Fatbrain.com, an Internet professional bookstore, stocks select product documentation from Sun Microsystems, Inc.

For a list of documents and how to order them, visit the Sun Documentation Center on Fatbrain.com at http://www1.fatbrain.com/documentation/sun.

Accessing Sun Documentation Online

The docs.sun.comSM Web site enables you to access Sun technical documentation online. You can browse the docs.sun.com archive or search for a specific book title or subject. The URL is http://docs.sun.com.

Getting Support for SunScreen Products

If you require technical support, contact your Sun sales representative or Sun Authorized Reseller. See

http://www.sun.com/service/contacting/index.html for information on contacting Sun and

http://internet.central.sun.com/service/support/index.html for information on Sun's support services.

Typographic Conventions

The following table describes the typographic changes used in this book.

Table P-1 Typographic Conventions

Typeface or Symbol 

Meaning 

Example 

AaBbCc123

 The names of commands, files, and directories; on-screen computer output

Edit your .login file.

Use ls -a to list all files.

machine_name% you have mail.

AaBbCc123

 What you type, contrasted with on-screen computer output

machine_name% su

Password:

AaBbCc123

 Command-line placeholder: replace with a real name or value

To delete a file, type rm filename.

AaBbCc123

Book titles, new words, or terms, or words to be emphasized. 

Read Chapter 6 in User's Guide.

These are called class options.

You must be root to do this.

Shell Prompts in Command Examples

The following table shows the default system prompt and superuser prompt for the C shell, Bourne shell, and Korn shell.

Table P-2 Shell Prompts

Shell 

Prompt 

 C shell promptmachine_name%
 C shell superuser promptmachine_name#
 Bourne shell and Korn shell prompt$
 Bourne shell and Korn shell superuser prompt#

Related Books and Publications

You may want to refer to the following sources for background information on network security, cryptography, and SKIP.