• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

CARP and user privilege

Scheduled Pinned Locked Moved HA/CARP/VIPs
3 Posts 2 Posters 1.1k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • J
    jjavier
    last edited by Oct 2, 2014, 2:59 PM

    Hello, all!

    I am in the middle of my first CARP setup.  The one thing that I noticed was Remote System Username, if you want to sync configuration settings.

    Security is a biggie in my company, and exposing a(nother) user that seems to require admin privileges doesn't seem very secure.

    Does anyone know the minimum privileges required for the user that can sync configuration between pfsense installation?

    Thanks ahead for your assistance.

    1 Reply Last reply Reply Quote 0
    • V
      viragomann
      last edited by Oct 7, 2014, 12:14 PM

      Hi!

      If you use a distinct interface for FW sync as it's suggested there will be no security issue with a user who have admin privileges.

      Furthermore if you have your WebConfigurator set to use HTTPS protocol the sync communication is also encrypted.

      1 Reply Last reply Reply Quote 0
      • J
        jjavier
        last edited by Oct 7, 2014, 3:29 PM

        Thank you for your reply.

        I am still not sure of the statement about having the distinctive interface - is there a way to bind a user to login only through specific interfaces, that I am unaware of?  As far as I see, a configured user can login through any allowed interface.

        HTTPS is good for encrypting the traffic, but exposing the system to yet another full admin user is what I need to secure.

        If a configured user can login through any interface, it would be nice to know what minimum privileges are needed for the CARP user.

        Thanks ahead of time for your replies.

        1 Reply Last reply Reply Quote 0
        2 out of 3
        • First post
          2/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
          This community forum collects and processes your personal information.
          consent.not_received