You can use the service_profile keyword to install a more secure system by restricting network services. This security option is only available for initial installations. An upgrade maintains all previously set services.
Use one of the following syntaxes to set this keyword.
limited_net specifies that all network services, except for Secure Shell, are either disabled or constrained to respond to local requests only. After installation, any individual network service can be enabled by using the svcadm and svccfg commands.
open specifies that no network service changes are made during installation.
If the service_profile keyword is not present in the sysidcfg file, no changes are made to the status of the network services during installation.
The network services can be enabled after installation by using the netservices open command or by enabling individual services by using SMF commands. See Revising Security Settings After Installation in Solaris 10 8/07 Installation Guide: Planning for Installation and Upgrade.
For further information about limiting network security during installation, see Planning Network Security in Solaris 10 8/07 Installation Guide: Planning for Installation and Upgrade. See also the following man pages.