In this recipe, we'll learn how to make NRPE listen on a specific IP address on a target host. This might be done on hosts with multiple interfaces in order to prevent spurious requests made to the nrpe
daemon from untrusted interfaces, perhaps the public Internet. It could also be appropriate for configuring the daemon only to listen on a trusted VPN interface.
This setup can be particularly useful when the server has an interface into a dedicated management network to which the monitoring server also has access, preventing the nrpe
daemon from responding to requests on other interfaces unnecessarily, and thereby closing a possible security hole.