1 |
Hello Kirk, |
2 |
Is there IPtables based port knocker? |
3 |
I dislike idea opening ports for this purpose because they can be distinguished by some way. |
4 |
Promiscuous mode port knockers consume a lot of processor and |
5 |
I don't think it's good for production server. |
6 |
|
7 |
KH> A port knocker of some sort is a much more secure solution that will |
8 |
KH> allow you to block all unwanted IP's but still allow for dynamic |
9 |
KH> addresses. There are port knockers that listen on various ports and |
10 |
KH> work like a combination lock to open the port, and there are others that |
11 |
KH> use a more secure one time pad "magic packet" kind of authentication to |
12 |
KH> open the port for your IP. It is more work to setup, but it is more |
13 |
KH> secure than just changing the port. Remember a few years ago when ssh |
14 |
KH> had a remote exploit? You probably shouldn't leave that port open. |
15 |
|
16 |
-- |
17 |
Best regards, |
18 |
boger mailto:boger@×××.ru |
19 |
|
20 |
-- |
21 |
gentoo-security@g.o mailing list |