SECURITY Questions !!!

Netizen

Member
Aug 16, 2012
88
0
6
I am running CSF firewall on the HW node and it has a checkup script which does some checks and suggest some solutions.
Those checks are primarily designed for a common LAMP server and not for PROXMOX, however this is a question to the staff:

Will those suggestions break something if I implement them?

Suggestions:


  1. WARNING /var/tmp should either be symlinked to /tmp or mounted as a filesystem
  2. WARNING /tmp should be mounted as a separate filesystem with the noexec,nosuid options set
  3. WARNING /dev/shm is not mounted with the noexec,nosuid options (currently: nosuid). You should modify the mountpoint in /etc/fstab for /dev/shm with those options and remount
  4. WARNING You have a local DNS server running but do not appear to have any recursion restrictions set. This is a security and performance risk and you should look at restricting recursive lookups to the local IP addresses only

No4 is really strange as I don't have DNS server running! Unless something is there which it shoudn't.

Comments?
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!