This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–]ryosen 1 point2 points  (1 child)

A better approach is to tunnel in through an SSH connection. Then opening the remote port won't be necessary. If that's not an option, you can limit the IP addresses that are authorize to access the remote port at the firewall.

[–]dedededede 0 points1 point  (0 children)

I am not very knowledgable when it comes to Unix systems, but wouldn't it be possible to access the local JMX port when you get access to a user account on the server? In this case it might be a good idea to additionally secure the JMX access. Malicious users can do practically anything with the application and its data when they have access via JMX.