You are not logged in.

#1 2006-05-03 12:51:40

FUBAR
Member
From: Belgium
Registered: 2004-12-08
Posts: 1,029
Website

cacti on a firewall/router, safe?

I'd like to get some nice graphical info about CPU, RAM, disk, netm ... usage on my Arch router. This firewalling gateway router watchmajig shares my broadband connection with my LAN.

I've been looking around and cacti looks pretty nice. Cacti needs a database to store its information though. Obviously, installing cacti and mysql impose a potential security risk for the router.

Can this be done without having to worry too much about security issues?


A bus station is where a bus stops.
A train station is where a train stops.
On my desk I have a workstation.

Offline

#2 2006-05-03 15:45:18

cactus
Taco Eater
From: t͈̫̹ͨa͖͕͎̱͈ͨ͆ć̥̖̝o̫̫̼s͈̭̱̞͍̃!̰
Registered: 2004-05-25
Posts: 4,622
Website

Re: cacti on a firewall/router, safe?

of course I am safe on a firewall...
oh wait..

... if you are going to have web access to the router/firewall...then yes.
There have been remote exploit vulns associated with cacti in the past.
For security, it would be recommended to have snmp enabled on the inside interface..with only allowances for read only polling from a single internal host..
and have that host running cacti and sql, fetching stats from the router/firewall via snmp (like mrtg).

But for a balance between security and usability, with thought to simpler architecture and not alot of extra machines laying around..
cacti with apache/lighttpd with an sql engine listening only on localhost..would be *ok*. Just keep cacti well updated, and maybe only access it with ssl and require password protection to get at it.. (apache htdigest perhaps).


"Be conservative in what you send; be liberal in what you accept." -- Postel's Law
"tacos" -- Cactus' Law
"t̥͍͎̪̪͗a̴̻̩͈͚ͨc̠o̩̙͈ͫͅs͙͎̙͊ ͔͇̫̜t͎̳̀a̜̞̗ͩc̗͍͚o̲̯̿s̖̣̤̙͌ ̖̜̈ț̰̫͓ạ̪͖̳c̲͎͕̰̯̃̈o͉ͅs̪ͪ ̜̻̖̜͕" -- -̖͚̫̙̓-̺̠͇ͤ̃ ̜̪̜ͯZ͔̗̭̞ͪA̝͈̙͖̩L͉̠̺͓G̙̞̦͖O̳̗͍

Offline

#3 2006-05-03 20:35:00

FUBAR
Member
From: Belgium
Registered: 2004-12-08
Posts: 1,029
Website

Re: cacti on a firewall/router, safe?

I wouldn't trust more than one of you on my box without a thread reassuring me. wink

I do have remote access to the box, but only on the internal interface. The web access would also be just for the LAN side.


A bus station is where a bus stops.
A train station is where a train stops.
On my desk I have a workstation.

Offline

#4 2006-05-08 13:21:25

FUBAR
Member
From: Belgium
Registered: 2004-12-08
Posts: 1,029
Website

Re: cacti on a firewall/router, safe?

I found an article on munin and monit. They seem to do the same as cacti, but without the need for a database. I'm going with those I think.


A bus station is where a bus stops.
A train station is where a train stops.
On my desk I have a workstation.

Offline

Board footer

Powered by FluxBB