Gentoo Archives: gentoo-security

From: boger <boger@×××.ru>
To: Kirk Hoganson <gentoo-security@l.g.o>
Subject: Re: [gentoo-security] [OT?] automatically firewalling off IPs
Date: Tue, 04 Oct 2005 16:34:13
Message-Id: 366975610.20051004202554@ttk.ru
In Reply to: Re: [gentoo-security] [OT?] automatically firewalling off IPs by Kirk Hoganson
1 Hello Kirk,
2 Is there IPtables based port knocker?
3 I dislike idea opening ports for this purpose because they can be distinguished by some way.
4 Promiscuous mode port knockers consume a lot of processor and
5 I don't think it's good for production server.
6
7 KH> A port knocker of some sort is a much more secure solution that will
8 KH> allow you to block all unwanted IP's but still allow for dynamic
9 KH> addresses. There are port knockers that listen on various ports and
10 KH> work like a combination lock to open the port, and there are others that
11 KH> use a more secure one time pad "magic packet" kind of authentication to
12 KH> open the port for your IP. It is more work to setup, but it is more
13 KH> secure than just changing the port. Remember a few years ago when ssh
14 KH> had a remote exploit? You probably shouldn't leave that port open.
15
16 --
17 Best regards,
18 boger mailto:boger@×××.ru
19
20 --
21 gentoo-security@g.o mailing list

Replies

Subject Author
Re: [gentoo-security] [OT?] automatically firewalling off IPs Kirk Hoganson <kirk2@×××××××××.com>