Cfengine tries to incorporate the TCP wrappers package if you have it on
your system. If you do, then the files /etc/hosts.allow
and
/etc/hosts.deny
allow you to give the cfengine/cfd service an extra
level of protection from `clever' spoofing attempts.