Ad Widget

Collapse

zabbix server on the internet

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • overrider
    Member
    • Oct 2006
    • 36

    #1

    zabbix server on the internet

    Hello,

    i run a zabbix server behind my nat router to monitor some machines on that lan. now i have a new server in a datacenter, and am considering opening the required ports in the nat-router and configure the server in the datacenter to log to the zabbix server in my lan. i know the data goes over the wire unencrypted, but tbh for just seeing diskspace and uptime and so on, to me it is not a big deal, or should it be? my main question is though, what kind of security issues i am facing when making my zabbix server available on the internet? can the zabbix server be screwed up somehow when it receives malicious packets? i know i could setup stunnel, but say i dont want to.

    thanks for any info,
    overrider
  • bbrendon
    Senior Member
    • Sep 2005
    • 870

    #2
    I have a zabbix server on the internet with port 10051 open. I've never had a in the 2 years it has been open but, this isn't to say I will NEVER have a problem.

    Maybe use Ip filter ? Wow. I just looked at my config and I'm not filtering it. Ouch. I think I should make some attempt to limit the zabbix port to at least 1% of the internet.

    But am I really at risk? Hmmm. I don't think any of the data I'm moving over the wire is secretive or very useful to hackers. My biggest concern would be, how secure is that zabbix port to buffer overflows, etc.
    Unofficial Zabbix Expert
    Blog, Corporate Site

    Comment

    • kurzhaarhippie
      Junior Member
      • Dec 2006
      • 14

      #3
      Without getting really close into zabbix yet I am using it within a openvpn tunnel over the internet. There is always a chance that buffer overflows could be used by some people and additional I do not think zabbix was coded with "high security" in mind. Just because it is mainly used in local networks and these are considered to be relatively safe.

      Every open port on your server could lead to a security hole. And the data zabbix agents and server exchange can give an attacker much needed information to get access over your machine.

      Securing your installation by a third party tool is in my opinion best way to do.

      Comment

      Working...