Presentation is loading. Please wait.

Presentation is loading. Please wait.

Technology Update TSAG Meeting 7/11/02. Announcements: DNS Naming and Cleanup (coming!)  imap: email, mail, mail1, mailsrv1  telnet, csun1: csun2, hp9k2,

Similar presentations


Presentation on theme: "Technology Update TSAG Meeting 7/11/02. Announcements: DNS Naming and Cleanup (coming!)  imap: email, mail, mail1, mailsrv1  telnet, csun1: csun2, hp9k2,"— Presentation transcript:

1 Technology Update TSAG Meeting 7/11/02

2 Announcements: DNS Naming and Cleanup (coming!)  imap: email, mail, mail1, mailsrv1  telnet, csun1: csun2, hp9k2, louie, huey Task: update all your mail clients to use the service-naming convention. Recent Problems with the Campus Mail System Emergency and Planned Maintenance Wednesday, July 10, 0001-0020 (this week) Saturday, July 12, 0001- 0600

3 Topics for Discussion Majordomo cleanup SPAM Access Control  Key Logging (Fed. Government Notice) Maintenance Window Training

4 Majordomo Cleanup Reason for Cleanup:  Spring cleaning  Preparing for “list serve” functionality to be supported by the Campus Directory  To minimize Campus expose to SPAM Some Stats:  Previous number of lists: > 4000  Current number of lists: 1047  Current number of entries: 39,398 Activities:  Message sent to all moderators, requesting cleanup of defunct lists  Probe message has been / will be sent to users (July 8) lists with the name matching “[0-9a-l]*” (July 17, 24, and 31) remaining lists

5 SPAM, SPAM, SPAM, Noticeable increase of inbound SPAM Ways to get mailing lists  cat /etc/passwd and /etc/alias  extract e-mail address from “finduser”  scrap mailto: links from web pagesmailto:  pull down e-mail address from http://web.csun.edu ‘s address book http://web.csun.edu  (non-authenticated) scrap e-mail address from http://www.csun.edu/peoplefinder http://www.csun.edu/peoplefinder Balancing act needed to address the situation

6 Campus SPAM Concerns There has been a sharp increase of SPAM from off- campus!  Can we block all mail from off campus?  Can we block all mail from “.com” domains?  Can we block all mail from msn.com?  Can we block all mail with words containing: Click, here, for, instance, access  Can we block all mail with the subject: “Hey its Anna”  Can we block all pornography? (Please define!) One Answer is “No that’s censorship!!!!” Users must use personal filter options

7 Access Control: We have made lots of progress – more to do! Recent Changes:  Blocking the following ports: NFS (2049)  Blocking all inbound network connections to: Subnet 9 (Sequoia Hall south) Subnet 10 (Sequoia Hall 1 st floor) Subnet 11 (Sequoia Hall 2 nd floor)  Partial Subnets blocking: 1,2,12,63,68,95,96,105 Key logging vulnerability reduced by:  Appropriate account/password controls for administrator and power user accounts  Blocking all inbound network connections to non Internet servers

8 Proposed Changes Block all inbound ports in the range: 1-19 Block all inbound ports for the following protocols: Jet Direct: 586 Flexlm: 744netbios-ssn: 2279 loc-srv: 2069svrloc: 433 ldap: 82ldaps: 636 Continue to work on phasing out “pcanywhere” Target date: August 2

9 Maintenance Window Proposal Should you work on a live system? Three possible Outages exist: 1. None(only academically) 2. Unplanned 3. Planned  Proper maintenance minimizes overall downtime.  Challenge: to find the intersection that minimizes disruptions to the campus community  Updated proposed window is Saturdays between 0001 – 0600 hours Feedback please!

10 Training


Download ppt "Technology Update TSAG Meeting 7/11/02. Announcements: DNS Naming and Cleanup (coming!)  imap: email, mail, mail1, mailsrv1  telnet, csun1: csun2, hp9k2,"

Similar presentations


Ads by Google