Differences
This shows you the differences between two versions of the page.
Next revision | Previous revision | ||
en:verejne:sit:ethernet [08.07.2018 14:27] – created Pavel Valach | en:verejne:sit:ethernet [08.10.2024 11:28] (current) – [Security] cesnet blokuje udp 631 english Karel Kopecký | ||
---|---|---|---|
Line 3: | Line 3: | ||
====== Cable connection ====== | ====== Cable connection ====== | ||
- | Members of Club Sincoolka | + | Members of Club Sincoolka |
- | Your device needs to be registered to access our cable network. Bring it to the LAB during office hours, or send us a request // | + | **Sinkuleho dormitory: |
- | - the MAC address of your Ethernet | + | **Dejvická dormitory:** only two Ethernet |
- | - what device you are connecting, | + | |
- | - that it will be connected using cable. | + | |
+ | If your device is registered, you'll be immediately connected to Internet straight away. If not, you should be redirected to our Information System - SINIS. | ||
- | ===== Installation manuals ===== | + | <note information> |
+ | Your device needs to be registered to access our cable network. Please follow the instructions at [[en: | ||
+ | </ | ||
- | {{indexmenu>: | + | <note important> |
+ | WiFi registered devices are not automatically registered for Ethernet, as they are separate network interfaces with different MAC addresses! | ||
+ | </ | ||
+ | |||
+ | Currently we only allow one Ethernet (cable-connected) device per user. | ||
+ | |||
+ | Also, if you need a cable, come to the LAB during office hours; we have a couple of them to give. ;) | ||
+ | |||
+ | ===== Security ===== | ||
+ | |||
+ | <note warning> | ||
+ | Your cable-connected device has a public IPv4 address, | ||
+ | __**always use a properly configured firewall!**__ | ||
+ | </ | ||
+ | |||
+ | <note important> | ||
+ | CESNET has decided to centraly block inbound connections to the UDP port 631 with regard to a serious vulnerability in CUPSd (CVE-2024-47176). | ||
+ | </ | ||
+ | |||
+ | All devices connected with an Ethernet cable get not only an IPv6 address, but a **public IPv4 address** as well, it is therefore necessary to **correctly configure the firewall** on such devices. Alas, people do not, so, unfortunately, | ||
+ | ^ Service | ||
+ | | FTP | TCP, | ||
+ | | Telnet | ||
+ | | SMTP | TCP, | ||
+ | | DNS | TCP, | ||
+ | | NetBIOS | ||
+ | | SMB (Samba) | ||
+ | | RDP (remote desktop) | ||
+ | | Microsoft SQL | TCP, | ||
+ | | OracleDB | ||
+ | | MySQL | TCP | 3306 | | ||
+ | | PostgreSQL | ||
+ | | Memcached | ||
+ | | MongoDB | ||
+ | | Redis | TCP | 6379 | | ||
+ | | HP JetDirect/ | ||
+ | | LPD/LPR (printing) | ||
+ | | IPP/CUPS (printing) | ||
+ | | UPnP | TCP, | ||
+ | | SLP | TCP, | ||
+ | | SNMP | UDP | 161, | ||
+ | | Other | TCP, | ||
+ | |||
+ | If you need to have one of these ports open, please visit us during the office hours or send us an email. | ||
+ | ===== How to find a MAC address ===== | ||
+ | |||
+ | A MAC address is an unique identifier of a network device. It is commonly written as a hexadecimal number, which may look for instance like this: | ||
+ | |||
+ | '' | ||
+ | |||
+ | {{indexmenu>: | ||
+ | |||
+ | If you are unable to find your device' |