Skip to Content.
Sympa Menu

perfsonar-user - Re: [perfsonar-user] memcached and firewall rules

Subject: perfSONAR User Q&A and Other Discussion

List archive

Re: [perfsonar-user] memcached and firewall rules


Chronological Thread 
  • From: Andrew Lake <>
  • To: Hervey Allen <>,
  • Subject: Re: [perfsonar-user] memcached and firewall rules
  • Date: Fri, 9 Feb 2018 06:18:06 -0800
  • Ironport-phdr: 9a23:6Qu35RPvn3kX7b0iA/wl6mtUPXoX/o7sNwtQ0KIMzox0Iv34rarrMEGX3/hxlliBBdydt6odzbKO+4nbGkU4qa6bt34DdJEeHzQksu4x2zIaPcieFEfgJ+TrZSFpVO5LVVti4m3peRMNQJW2aFLduGC94iAPERvjKwV1Ov71GonPhMiryuy+4ZLebxlViDanfb9+MAi9oBnMuMURnYZsMLs6xAHTontPdeRWxGdoKkyWkh3h+Mq+/4Nt/jpJtf45+MFOTav1f6IjTbxFFzsmKHw65NfqtRbYUwSC4GYXX3gMnRpJBwjF6wz6Xov0vyDnuOdxxDWWMMvrRr0vRz+s87lkRwPpiCcfNj427mfXitBrjKlGpB6tvgFzz5LIbI2QMvd1Y6HTcs4ARWdZXsheVSJBDISzYIUBDOQPIPhWoJXmqlQUsRezHxOhCfnzxjJKgHL9wK000/4mEQHDxAEtA9QOv2nOrNrrOqYZTOa7w7PLzTrdcvhb3i3y6I7VfREhuvyDQ6lwfdDXyUYxCwPIl1OdopHrMTOS0+QCqWmb7+x4WOKpkG4nsR1+riKoxsc2hYnFnpoVxU7e9SV324Y1Itu4R1RhYdK+FptfqT2aOo1rSc0hW2FloDs2xqMFtJKhciUG0psqywPFZ/GGcIWE+gzvWPqVLDtih39oeKiziwiv/UWv0OHxVNe43VBXpSRfiNbMrGoC1xnL58iHVPR9+kCh1C6B1w/N5OxIO0Q0mrHfK5I7zb4wkYQTvVzCHi/whkr2kLebelg69uWr8ejqbK/qq5CBO4NuiwzzMbwimsmlDuQ5NggOUXKb+eO51LD750L5RqhFj/0tn6bHq5DWP8IbqbClAwNNyIYs9w6/Dyu60NQfhXQHNExKeAiJj4jyPFHOJur3De2mj1Sxizdk2erGM6blApXMNXjDjKzhcahn505dzgoz0c5Q54hSCr4fPPL/RFX9u8LFAR8kYESIxLPHBc9j25JWcGaLD6nRZKPfq0GF98opOPOHIogPt2C5Y+Ao/fD1inkwgxoAZqSz9ZoRdH2iGPl6eQOUbWe/rM0GFDIjuAYkQfOirFSBXHYHbnC+Toox/Xc9BZ7wXtSLfZyknLHUhHTzJZZRfG0TTwnUSXo=

Hi,

The only things that needs access to memcached comes from localhost. The esmond archiving plugin in pscheduler uses it as a cache between archiving processes to speed-up some requests. You can safely block it.

For a list of the ports that need to be open see http://docs.perfsonar.net/manage_security.html. If you would like a default set of firewall rules installed for you run ‘yum install perfsonar-toolkit-security’ on your testpoint which will setup rules on the host that only allow the listed ports through.

Hope that helps,
Andy



On February 8, 2018 at 4:54:03 PM, Hervey Allen () wrote:

Hi All - Our IT Security group contacted us to say that the memcached
process was open on our perfSONAR Testpoint bundle instance we had
installed.

It is...

Question - I have the perfSONAR default firewall rules in place. This is
running on a CentOS 7 box. What specifically needs to talk to this
service? Is this a service that is installed with Postgres? That's what
I think is happening.

Does Esmond need access to memcache from an archive host? Anything else?
Based on the release notes for 4.0rc3:

"Added memcached support to esmond archiver for tracking metadata
objects already created in order to increase archiver performance"

I think this is the case.

I'm trying to figure out proper strategy for recommending what to do
with the open memcached service.

I believe adding a firewall rule to only allow access to memcached on
the perfSONAR Testpoint Bundle node and from wherever we have Esmond is
what makes sense?

Comments or recommendations are most welcome.

Thank you!

- Hervey



Network Startup Resource Center
https://nsrc.org/



Archive powered by MHonArc 2.6.19.

Top of Page